PT-2026-93369 · Nlnet · Unbound
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.13.2 through 1.26.1
Description
Zones configured with
zonemd-check: yes that are located below a trust anchor contain a flaw where tampered zone contents may be served or stored to disk before the ZONEMD integrity check is completed. This occurs due to the asynchronous resolution of DS/DNSKEY records required for the check. If the zonefile: option is used to write a zonefile to disk while the ZONEMD check fails, the tampered data is reloaded upon startup and remains available until the next verification concludes. Even if verification subsequently fails, the tampered data persists on disk for future reloads.Recommendations
Update NLnet Labs Unbound to a version later than 1.26.1.
As a temporary mitigation, avoid using the
zonefile: option for zones configured with zonemd-check: yes that are located below a trust anchor.Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound