PT-2026-42130 · Nlnet+4 · Unbound+4
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions prior to 1.25.1
Description
A flaw in the DNSSEC validator occurs when the code path used to consult the negative cache for DS records ignores the limit on NSEC3 hash calculations. An attacker controlling a DNSSEC signed zone can exploit this by signing NSEC3 records with high iterations for child delegations and querying the system. This causes the software to perform excessive hash calculations, holding a global lock for the negative cache and blocking other threads. This results in service degradation and can lead to a denial of service through coordinated attacks.
Recommendations
Update to version 1.25.1.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Linuxmint
Red Os
Ubuntu
Unbound