CVE-2018-20103: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
- Haproxy Haproxy: up to and including 1.8.14
- Red Hat Openshift Container Platform: version 3.11 only
Published 2018-12-12. Last modified 2026-06-17.