Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w62x-5q5r-fgmp

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

EPSS

Процентиль: 3%
0.00128
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 22 часов назад

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

CVSS3: 4.4
redhat
1 день назад

A flaw was found in Unbound. This vulnerability affects ZONEMD configured zones that are located below a trust anchor, allowing tampered zone contents to be served or stored to disk before integrity checks are completed. This occurs due to the asynchronous resolution of DS/DNSKEY records, which creates a window where the integrity check is not yet finalized. Consequently, if a zone file is written to disk while the ZONEMD check has not yet completed or failed, the compromised data can be reloaded on startup and remain available until ZONEMD verification concludes again, potentially leading to the serving of incorrect DNS information.

CVSS3: 4.4
nvd
1 день назад

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

CVSS3: 4.4
debian
1 день назад

Описание отсутствует

EPSS

Процентиль: 3%
0.00128
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-345