CVE-2018-20103: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
  • Haproxy Haproxy: up to and including 1.8.14
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2018-12-12. Last modified 2026-06-17.