PT-2026-63373 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.16.2 through 1.25.1
Description
An issue exists within the ghost domain names family of attacks where an adversary controlling a ghost zone can extend the ghost domain window for A/AAAA glue records. By sending a single client A/AAAA query, the attacker can cause the system to overwrite the cached expired parent-side glue rrset, extending the window by up to one cached TTL configured value, specifically the
cache-max-ttl variable. In configurations where harden-referral-path: yes is enabled, the issue can be triggered without a client query as the system performs the query implicitly.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound