PT-2026-63378 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.6.0 through 1.25.1
Description
A flaw exists where a replay of a wildcard rrset (Resource Record Set) can be briefly marked as DNSSEC secure based solely on RRSIG (Resource Record Signature) validation and stored in the cache before NSEC (Next Secure) validation identifies it as bogus. This occurs when a resolving thread marks an rrset as secure and another thread on the serve expired path retrieves these updated contents for a reply. An attacker can exploit this to change a specific record adjacent to a wildcard into that wildcard. This is achieved by using a DNSSEC-signed domain and a CNAME wrapper record pointing to a record next to a wildcard. By querying for the wildcard sibling record and later injecting a wildcard replay into a response for the CNAME wrapper after expiry, the poisoned rrset is marked secure and points to the wildcard. This issue specifically affects the serve expired path and requires the injection of a signed wildcard rrset without the accompanying NSEC rrset.
Recommendations
Update NLnet Labs Unbound to a version later than 1.25.1.
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound