In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unbound | Nlnetlabs | * | 1.26.1 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | unbound-0:1.24.2-7.el10_2.6 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | unbound-0:1.20.0-18.el10_0.13 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | unbound-0:1.6.6-5.el7_9.2 | * |
| Red Hat Enterprise Linux 8 | RedHat | unbound-0:1.16.2-5.14.el8_10.4 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | unbound-0:1.7.3-15.el8_4.4 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | unbound-0:1.7.3-15.el8_4.4 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | unbound-0:1.7.3-17.el8_6.8 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | unbound-0:1.7.3-17.el8_6.8 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | unbound-0:1.16.2-5.el8_8.6 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | unbound-0:1.16.2-5.el8_8.6 | * |
| Red Hat Enterprise Linux 9 | RedHat | unbound-0:1.24.2-3.el9_8.8 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | unbound-0:1.16.2-3.el9_2.6 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | unbound-0:1.16.2-8.el9_4.3 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | unbound-0:1.16.2-19.el9_6.2 | * |
| Red Hat Hardened Images | RedHat | unbound-main-1.26.1-1.hum1 | * |
| Unbound | Ubuntu | esm-infra-legacy/trusty | * |
| Unbound | Ubuntu | esm-infra-legacy/xenial | * |
| Unbound | Ubuntu | esm-infra/bionic | * |
| Unbound | Ubuntu | esm-infra/focal | * |
| Unbound | Ubuntu | jammy | * |
| Unbound | Ubuntu | noble | * |
| Unbound | Ubuntu | resolute | * |
| Unbound | Ubuntu | upstream | * |