Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unbound | Nlnetlabs | * | 1.9.5 (excluding) |
| Red Hat Enterprise Linux 8 | RedHat | unbound-0:1.7.3-15.el8 | * |
| Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | unbound-0:1.7.3-12.el8_2 | * |
| Unbound | Ubuntu | bionic | * |
| Unbound | Ubuntu | esm-infra/bionic | * |
| Unbound | Ubuntu | esm-infra/focal | * |
| Unbound | Ubuntu | focal | * |
| Unbound | Ubuntu | trusty | * |
| Unbound | Ubuntu | upstream | * |
| Unbound | Ubuntu | xenial | * |