In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the dnscrypt: clause lists more dnscrypt-provider-cert: files than there are matching dnscrypt-secret-key: files, Unbound fills only the matched prefix and leaves the tail slots at the 0xdb fill that libsodiums allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with 0xdb bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are 0xdb to dnscrypt-port will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support (–enable-dnscrypt).
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unbound | Ubuntu | upstream | * |