In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the serve-expired code path can cause a double decrement on the wait-limit counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each slow query, one the attackers authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the serve-expired path and decrements the counter twice. This second query was named pump. By alternating slow queries and pumps, the attacker keeps the per-client counter at or below the configured wait-limit indefinitely, and can hold an arbitrary number of pending queries from a single source IP, up to the global mesh quota (num-queries-per-thread); eventually bypassing one of the counter measures introduced for DNSBomb (CVE-2024-33655). This vulnerability is present on the serve-expired code path.
The product performs the same operation on a resource two or more times, when the operation should only be applied once.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unbound | Nlnetlabs | 1.20.0 (including) | 1.26.1 (excluding) |
| Red Hat Hardened Images | RedHat | unbound-main-1.26.1-1.hum1 | * |
| Unbound | Ubuntu | upstream | * |