PT-2026-63393 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.20.0 through 1.25.1
Description
An issue exists when the software is configured with
serve-expired: yes and serve-expired-client-timeout is greater than discard-timeout (where discard-timeout is greater than 0). In this specific configuration, the discard-timeout branch within the serve expired logic drops an aged client reply without correctly decrementing the counter for the number of reply addresses for the query. Because the counter is not decremented, it can reach its maximum limit, causing new clients for duplicate in-flight queries to be silently dropped, which leads to a degradation of the resolution service. A malicious actor can trigger this by querying the resolver for a client-controlled slow-on-demand authoritative zone to push the counter past the threshold.Recommendations
Update NLnet Labs Unbound to a version later than 1.25.1.
Ensure that
serve-expired-client-timeout is not configured to be greater than discard-timeout when serve-expired is enabled.Fix
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound