PT-2026-63377 · Nlnet+1 · Unbound+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.7.0 through 1.25.1
Description
Insufficient validation of the
RRSIG.Labels field and premature cache writes during RFC 8198 aggressive NSEC processing enable cache poisoning. An attacker controlling a single delegated zone under an NSEC-signed parent domain can poison arbitrary sibling zones. By using fraudulent wildcard DS records with fewer labels than expected or an unknown algorithm, the attacker can create insecure existence for non-existent delegations covered by the parent's NSEC chain, allowing the injection of insecure wildcard records for those delegations.Recommendations
Update NLnet Labs Unbound to a version later than 1.25.1.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Unbound