PT-2026-63383 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions prior to 1.25.2
Description
When the
unwanted-reply-threshold is enabled and set to a value greater than zero, the software is susceptible to a cache clearing attack. A malicious actor controlling a delegation that returns in-bailiwick glue records of 0.0.0.0/::0 can trigger a defensive cache clear of the message and rrset caches. This occurs because the system may route traffic for 0.0.0.0/::0 via loopback, causing the listener to answer from 127.0.0.1. The mismatch between the source IP 0.0.0.0 and the reply IP 127.0.0.1 leads the software to categorize the reply as unwanted. By repeatedly triggering this behavior, an attacker can force the unwanted-reply-threshold counter to its limit, clearing the cache indefinitely without needing to send spoofed packets.Recommendations
Update to version 1.25.2 or later.
As a temporary mitigation, set the
unwanted-reply-threshold to zero to disable the affected functionality.Fix
DoS
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound