PT-2026-63375 · Nlnet · Unbound+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions prior to 1.25.2
Description
Applications using
libunbound configured with the unwanted-reply-threshold parameter may be abruptly terminated. This occurs when the threshold is reached and libunbound attempts to call the libworker alloc cleanup() function, which is missing from the function call allow list. The issue is triggered when the unwanted-reply-threshold is set to a non-zero value and the iterator queries an authoritative server that sends enough UDP datagrams with incorrect transaction IDs to exceed that threshold, resulting in a fatal exit of libunbound and the termination of the embedding application.Recommendations
Update to version 1.25.2 or later.
As a temporary workaround, set the
unwanted-reply-threshold parameter to zero.Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound
Libunbound