Logo
vulnerabilityCVE-2026-33811
Name
CVE-2026-33811
Source
NVD ( link)Debian ( link)
Description
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
golang-bootstrap
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Exploitable
openwrt
master
1.26.4-r1
Not Affected
yocto
kirkstone
1.17.13
Exploitable
yocto
kirkstone
1.17.13
Exploitable
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Patched
yocto
scarthgap
1.22.12
Exploitable

Resolved with patches#


go (yocto:scarthgap)

#
Title
Author
Resolve
1
net: avoid double-free of cgo pointer when handling large DNS
Damien Neil <dneil@google.com>
CVE-2026-33811