PT-2026-63372 · Nlnet · Unbound
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.22.0 through 1.25.1
Description
Client terminated DNS-over-QUIC (DoQ) queries are not accounted for properly, leading to an inflation of the waiting number of replies for in-flight resolution queries. This causes a degradation of resolution services for new clients. An attacker can trigger this by issuing DoQ queries and immediately terminating them using STOP SENDING, RESET STREAM, or CONNECTION CLOSE QUIC frames. Once the maximum limit is reached, new queries for in-flight resolutions are silently dropped. This issue requires the software to be compiled with DoQ support via
--with-libngtcp2 and the quic-port to be configured. Additionally, the attacker must use multiple source IPs to bypass the wait-limit option.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound