PT-2026-63390 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.7.0 through 1.25.1
Description
When the
dnscrypt: clause contains more dnscrypt-provider-cert: files than matching dnscrypt-secret-key: files, the software fails to properly initialize all slots, leaving some filled with 0xdb bytes from the libsodium allocator. Because the system iterates based on the number of certificate files rather than actual initialized slots, it may access these garbage entries. An unauthenticated client can trigger a server crash by sending a UDP datagram of 68 bytes or more to the dnscrypt-port where the first 8 bytes are 0xdb, leading to a garbage dereference. This issue requires the software to be compiled with DNSCrypt support using the --enable-dnscrypt flag.Recommendations
Update NLnet Labs Unbound to a version later than 1.25.1.
Ensure that the number of
dnscrypt-provider-cert: files does not exceed the number of dnscrypt-secret-key: files in the dnscrypt: configuration clause.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound