PT-2026-63384 · Nlnet · Unbound

·

CVE-2026-50252

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

9.3

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.4.22 through 1.25.1
Description An issue exists where the secrecy of the randomized UDP source port, used to increase entropy in DNS transactions, is undermined when resolver load balancing policies depend on the source port. This occurs when the so-reuseport: yes configuration option is enabled, which is the default setting. Unbound partitions the UDP source port space into disjoint subsets assigned to specific worker threads. Because the kernel's SO REUSEPORT mechanism deterministically assigns queries to threads, the source port of an outgoing query to an authoritative name server reveals which worker thread processed the original client query. A malicious actor can map incoming UDP source ports to specific worker threads to facilitate DNS cache poisoning attacks by reducing the effective random port population per thread.
Recommendations For versions 1.4.22 through 1.25.1, disable the so-reuseport option by setting it to no in the configuration to mitigate the risk of DNS cache poisoning.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92982
CVE-2026-50252
ECHO-A6ED-1CEA-98BC
OESA-2026-3232
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound