<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2025-47950</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2025-47950</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>6</Number>
        <Date>2026-03-05T00:33:01Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-06-10T23:12:46Z</InitialReleaseDate>
    <CurrentReleaseDate>2026-03-05T00:33:01Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2025-47950</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream without imposing any limits on the number of concurrent streams or goroutines. A remote, unauthenticated attacker could open a large number of streams, leading to uncontrolled memory consumption and eventually causing an Out Of Memory (OOM) crash - especially in containerized or memory-constrained environments. The patch in version 1.12.2 introduces two key mitigation mechanisms: `max_streams`, which caps the number of concurrent QUIC streams per connection with a default value of `256`; and `worker_pool_size`, which Introduces a server-wide, bounded worker pool to process incoming streams with a default value of `1024`. This eliminates the 1:1 stream-to-goroutine model and ensures that CoreDNS remains resilient under high concurrency.  Some workarounds are available for those who are unable to upgrade. Disable QUIC support by removing or commenting out the `quic://` block in the Corefile, use container runtime resource limits to detect and isolate excessive memory usage, and/or monitor QUIC connection patterns and alert on anomalies.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <Branch Type="Product Name" Name="Container suse/sl-micro/6.0/baremetal-os-container:latest">
        <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest">Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-Azure">
      <Branch Type="Product Name" Name="Image SLE-Micro-Azure">
        <FullProductName ProductID="Image SLE-Micro-Azure">Image SLE-Micro-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLE-Micro-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLE-Micro-BYOS-Azure">
        <FullProductName ProductID="Image SLE-Micro-BYOS-Azure">Image SLE-Micro-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 16.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 16.0">
        <FullProductName ProductID="SUSE Linux Enterprise Server 16.0" CPE="cpe:/o:suse:sles:16:16.0:server">SUSE Linux Enterprise Server 16.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="govulncheck-vulndb-0.0.20250612T141001-1.1">
      <FullProductName ProductID="govulncheck-vulndb-0.0.20250612T141001-1.1">govulncheck-vulndb-0.0.20250612T141001-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="govulncheck-vulndb-0.0.20250814T182633-160000.1.2">
      <FullProductName ProductID="govulncheck-vulndb-0.0.20250814T182633-160000.1.2">govulncheck-vulndb-0.0.20250814T182633-160000.1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-all-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-all-20241128-slfo.1.1_2.1">kernel-firmware-all-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-amdgpu-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-amdgpu-20241128-slfo.1.1_2.1">kernel-firmware-amdgpu-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-ath10k-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-ath10k-20241128-slfo.1.1_2.1">kernel-firmware-ath10k-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-ath11k-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-ath11k-20241128-slfo.1.1_2.1">kernel-firmware-ath11k-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-ath12k-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-ath12k-20241128-slfo.1.1_2.1">kernel-firmware-ath12k-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-atheros-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-atheros-20241128-slfo.1.1_2.1">kernel-firmware-atheros-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-bluetooth-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-bluetooth-20241128-slfo.1.1_2.1">kernel-firmware-bluetooth-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-bnx2-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-bnx2-20241128-slfo.1.1_2.1">kernel-firmware-bnx2-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-brcm-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-brcm-20241128-slfo.1.1_2.1">kernel-firmware-brcm-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-chelsio-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-chelsio-20241128-slfo.1.1_2.1">kernel-firmware-chelsio-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-dpaa2-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-dpaa2-20241128-slfo.1.1_2.1">kernel-firmware-dpaa2-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-i915-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-i915-20241128-slfo.1.1_2.1">kernel-firmware-i915-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-intel-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-intel-20241128-slfo.1.1_2.1">kernel-firmware-intel-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1">kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-liquidio-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-liquidio-20241128-slfo.1.1_2.1">kernel-firmware-liquidio-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-marvell-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-marvell-20241128-slfo.1.1_2.1">kernel-firmware-marvell-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-media-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-media-20241128-slfo.1.1_2.1">kernel-firmware-media-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-mediatek-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-mediatek-20241128-slfo.1.1_2.1">kernel-firmware-mediatek-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-mellanox-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-mellanox-20241128-slfo.1.1_2.1">kernel-firmware-mellanox-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-mwifiex-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-mwifiex-20241128-slfo.1.1_2.1">kernel-firmware-mwifiex-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-network-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-network-20241128-slfo.1.1_2.1">kernel-firmware-network-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-nfp-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-nfp-20241128-slfo.1.1_2.1">kernel-firmware-nfp-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-nvidia-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-nvidia-20241128-slfo.1.1_2.1">kernel-firmware-nvidia-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-platform-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-platform-20241128-slfo.1.1_2.1">kernel-firmware-platform-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-prestera-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-prestera-20241128-slfo.1.1_2.1">kernel-firmware-prestera-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-qcom-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-qcom-20241128-slfo.1.1_2.1">kernel-firmware-qcom-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-qlogic-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-qlogic-20241128-slfo.1.1_2.1">kernel-firmware-qlogic-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-radeon-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-radeon-20241128-slfo.1.1_2.1">kernel-firmware-radeon-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-realtek-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-realtek-20241128-slfo.1.1_2.1">kernel-firmware-realtek-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-serial-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-serial-20241128-slfo.1.1_2.1">kernel-firmware-serial-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-sound-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-sound-20241128-slfo.1.1_2.1">kernel-firmware-sound-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-ti-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-ti-20241128-slfo.1.1_2.1">kernel-firmware-ti-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-ueagle-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-ueagle-20241128-slfo.1.1_2.1">kernel-firmware-ueagle-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-firmware-usb-network-20241128-slfo.1.1_2.1">
      <FullProductName ProductID="kernel-firmware-usb-network-20241128-slfo.1.1_2.1">kernel-firmware-usb-network-20241128-slfo.1.1_2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python311-dnspython-2.4.2-2.1">
      <FullProductName ProductID="python311-dnspython-2.4.2-2.1">python311-dnspython-2.4.2-2.1</FullProductName>
    </Branch>
    <Relationship ProductReference="kernel-firmware-all-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-all-20241128-slfo.1.1_2.1">kernel-firmware-all-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-amdgpu-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-amdgpu-20241128-slfo.1.1_2.1">kernel-firmware-amdgpu-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-ath10k-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath10k-20241128-slfo.1.1_2.1">kernel-firmware-ath10k-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-ath11k-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath11k-20241128-slfo.1.1_2.1">kernel-firmware-ath11k-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-ath12k-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath12k-20241128-slfo.1.1_2.1">kernel-firmware-ath12k-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-atheros-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-atheros-20241128-slfo.1.1_2.1">kernel-firmware-atheros-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-bluetooth-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-bluetooth-20241128-slfo.1.1_2.1">kernel-firmware-bluetooth-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-bnx2-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-bnx2-20241128-slfo.1.1_2.1">kernel-firmware-bnx2-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-brcm-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-brcm-20241128-slfo.1.1_2.1">kernel-firmware-brcm-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-chelsio-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-chelsio-20241128-slfo.1.1_2.1">kernel-firmware-chelsio-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-dpaa2-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-dpaa2-20241128-slfo.1.1_2.1">kernel-firmware-dpaa2-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-i915-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-i915-20241128-slfo.1.1_2.1">kernel-firmware-i915-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-intel-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-intel-20241128-slfo.1.1_2.1">kernel-firmware-intel-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1">kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-liquidio-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-liquidio-20241128-slfo.1.1_2.1">kernel-firmware-liquidio-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-marvell-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-marvell-20241128-slfo.1.1_2.1">kernel-firmware-marvell-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-media-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-media-20241128-slfo.1.1_2.1">kernel-firmware-media-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-mediatek-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mediatek-20241128-slfo.1.1_2.1">kernel-firmware-mediatek-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-mellanox-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mellanox-20241128-slfo.1.1_2.1">kernel-firmware-mellanox-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-mwifiex-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mwifiex-20241128-slfo.1.1_2.1">kernel-firmware-mwifiex-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-network-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-network-20241128-slfo.1.1_2.1">kernel-firmware-network-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-nfp-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-nfp-20241128-slfo.1.1_2.1">kernel-firmware-nfp-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-nvidia-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-nvidia-20241128-slfo.1.1_2.1">kernel-firmware-nvidia-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-platform-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-platform-20241128-slfo.1.1_2.1">kernel-firmware-platform-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-prestera-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-prestera-20241128-slfo.1.1_2.1">kernel-firmware-prestera-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-qcom-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-qcom-20241128-slfo.1.1_2.1">kernel-firmware-qcom-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-qlogic-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-qlogic-20241128-slfo.1.1_2.1">kernel-firmware-qlogic-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-radeon-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-radeon-20241128-slfo.1.1_2.1">kernel-firmware-radeon-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-realtek-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-realtek-20241128-slfo.1.1_2.1">kernel-firmware-realtek-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-serial-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-serial-20241128-slfo.1.1_2.1">kernel-firmware-serial-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-sound-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-sound-20241128-slfo.1.1_2.1">kernel-firmware-sound-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-ti-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ti-20241128-slfo.1.1_2.1">kernel-firmware-ti-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-ueagle-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ueagle-20241128-slfo.1.1_2.1">kernel-firmware-ueagle-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-firmware-usb-network-20241128-slfo.1.1_2.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sl-micro/6.0/baremetal-os-container:latest">
      <FullProductName ProductID="Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-usb-network-20241128-slfo.1.1_2.1">kernel-firmware-usb-network-20241128-slfo.1.1_2.1 as a component of Container suse/sl-micro/6.0/baremetal-os-container:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="python311-dnspython-2.4.2-2.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-Azure">
      <FullProductName ProductID="Image SLE-Micro-Azure:python311-dnspython-2.4.2-2.1">python311-dnspython-2.4.2-2.1 as a component of Image SLE-Micro-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="python311-dnspython-2.4.2-2.1" RelationType="Default Component Of" RelatesToProductReference="Image SLE-Micro-BYOS-Azure">
      <FullProductName ProductID="Image SLE-Micro-BYOS-Azure:python311-dnspython-2.4.2-2.1">python311-dnspython-2.4.2-2.1 as a component of Image SLE-Micro-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="govulncheck-vulndb-0.0.20250814T182633-160000.1.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2">govulncheck-vulndb-0.0.20250814T182633-160000.1.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="govulncheck-vulndb-0.0.20250612T141001-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:govulncheck-vulndb-0.0.20250612T141001-1.1">govulncheck-vulndb-0.0.20250612T141001-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream without imposing any limits on the number of concurrent streams or goroutines. A remote, unauthenticated attacker could open a large number of streams, leading to uncontrolled memory consumption and eventually causing an Out Of Memory (OOM) crash - especially in containerized or memory-constrained environments. The patch in version 1.12.2 introduces two key mitigation mechanisms: `max_streams`, which caps the number of concurrent QUIC streams per connection with a default value of `256`; and `worker_pool_size`, which Introduces a server-wide, bounded worker pool to process incoming streams with a default value of `1024`. This eliminates the 1:1 stream-to-goroutine model and ensures that CoreDNS remains resilient under high concurrency.  Some workarounds are available for those who are unable to upgrade. Disable QUIC support by removing or commenting out the `quic://` block in the Corefile, use container runtime resource limits to detect and isolate excessive memory usage, and/or monitor QUIC connection patterns and alert on anomalies.</Note>
    </Notes>
    <CVE>CVE-2025-47950</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-all-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-amdgpu-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath10k-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath11k-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ath12k-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-atheros-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-bluetooth-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-bnx2-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-brcm-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-chelsio-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-dpaa2-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-i915-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-intel-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-iwlwifi-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-liquidio-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-marvell-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-media-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mediatek-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mellanox-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-mwifiex-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-network-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-nfp-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-nvidia-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-platform-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-prestera-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-qcom-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-qlogic-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-radeon-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-realtek-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-serial-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-sound-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ti-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-ueagle-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Container suse/sl-micro/6.0/baremetal-os-container:latest:kernel-firmware-usb-network-20241128-slfo.1.1_2.1</ProductID>
        <ProductID>Image SLE-Micro-Azure:python311-dnspython-2.4.2-2.1</ProductID>
        <ProductID>Image SLE-Micro-BYOS-Azure:python311-dnspython-2.4.2-2.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:govulncheck-vulndb-0.0.20250814T182633-160000.1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:govulncheck-vulndb-0.0.20250612T141001-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
