CVE Vulnerabilities

CVE-2025-5994

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Jul 16, 2025 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A multi-vendor cache poisoning vulnerability named Rebirthday Attack has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., –enable-subnet, AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the send-client-subnet, client-subnet-zone or client-subnet-always-forward options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatunbound-0:1.20.0-12.el10_0*
Red Hat Enterprise Linux 8RedHatunbound-0:1.16.2-5.9.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatunbound-0:1.7.3-12.el8_2.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatunbound-0:1.7.3-15.el8_4.2*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatunbound-0:1.7.3-15.el8_4.2*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatunbound-0:1.7.3-17.el8_6.6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatunbound-0:1.7.3-17.el8_6.6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatunbound-0:1.7.3-17.el8_6.6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatunbound-0:1.16.2-5.el8_8.5*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatunbound-0:1.16.2-5.el8_8.5*
Red Hat Enterprise Linux 9RedHatunbound-0:1.16.2-19.el9_6.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatunbound-0:1.13.1-13.el9_0.5*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatunbound-0:1.16.2-3.el9_2.5*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatunbound-0:1.16.2-8.el9_4.2*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202510291903-0*
Red Hat OpenShift Container Platform 4.13RedHatrhcos-413.92.202510150118-0*
Red Hat OpenShift Container Platform 4.14RedHatrhcos-414.92.202510211419-0*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202510112152-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202510230424-0*
Red Hat OpenShift Container Platform 4.19RedHatrhcos-4.19.9.6.202510140714-0*
Red Hat OpenShift Container Platform 4.20RedHatrhcos-4.20.9.6.202509251656-0*
UnboundUbuntudevel*
UnboundUbuntujammy*
UnboundUbuntunoble*
UnboundUbuntuplucky*
UnboundUbuntuquesting*
UnboundUbuntuupstream*

References