CVE-2026-33811: CWE-415: Double Free in Go standard library net
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
AI Analysis
Technical Summary
This vulnerability in the Go net package arises from a double-free memory error triggered by a very long CNAME response when using the LookupCNAME function with the cgo DNS resolver. The flaw allows a remote attacker to cause a crash of the affected application, resulting in a denial of service. The issue is specific to applications using the cgo DNS resolver. The vendor advisory recommends mitigating the issue by configuring applications to use the pure Go DNS resolver instead, via the environment variable GODEBUG=netdns=go. This mitigation requires restarting the affected applications. The vulnerability has a CVSS v3.1 base score of 7.5, indicating high severity, with no impact on confidentiality or integrity but a high impact on availability.
Potential Impact
A remote attacker can cause a denial of service by triggering a double-free memory error through a very long CNAME DNS response. This leads to a crash of the vulnerable application, impacting service availability. There is no confidentiality or integrity impact reported.
Mitigation Recommendations
A fix is available via configuration change: applications should be configured to use the pure Go DNS resolver instead of the cgo DNS resolver by setting the environment variable GODEBUG=netdns=go. This mitigation requires restarting affected applications or services. Users should verify that this change does not negatively affect DNS resolution in their environment. No official patch is explicitly stated in the advisory, but this configuration change effectively mitigates the vulnerability.
CVE-2026-33811: CWE-415: Double Free in Go standard library net
Description
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVSS v3.1
Score 7.5high
Affected software
Go standard library
net
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the Go net package arises from a double-free memory error triggered by a very long CNAME response when using the LookupCNAME function with the cgo DNS resolver. The flaw allows a remote attacker to cause a crash of the affected application, resulting in a denial of service. The issue is specific to applications using the cgo DNS resolver. The vendor advisory recommends mitigating the issue by configuring applications to use the pure Go DNS resolver instead, via the environment variable GODEBUG=netdns=go. This mitigation requires restarting the affected applications. The vulnerability has a CVSS v3.1 base score of 7.5, indicating high severity, with no impact on confidentiality or integrity but a high impact on availability.
Potential Impact
A remote attacker can cause a denial of service by triggering a double-free memory error through a very long CNAME DNS response. This leads to a crash of the vulnerable application, impacting service availability. There is no confidentiality or integrity impact reported.
Mitigation Recommendations
A fix is available via configuration change: applications should be configured to use the pure Go DNS resolver instead of the cgo DNS resolver by setting the environment variable GODEBUG=netdns=go. This mitigation requires restarting affected applications or services. Users should verify that this change does not negatively affect DNS resolution in their environment. No official patch is explicitly stated in the advisory, but this configuration change effectively mitigates the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-03-23T20:35:32.814Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-33811","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33120","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33123","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33142","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:33150","vendor":"Red Hat"}]
Threat ID: 69fcf0c1cbff5d86102bd5ac
Added to database: 05/07/2026, 20:06:25 UTC
Last enriched: 08/14/2026, 13:07:28 UTC
Last updated: 09/11/2026, 01:30:14 UTC
Views: 241
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.