Описание
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
A flaw was found in NLnet Labs Unbound. A remote attacker, by controlling a malicious domain (a "ghost zone") and querying a vulnerable Unbound server, could exploit a vulnerability related to "ghost domain names" attacks. This could allow the attacker to overwrite cached Name Server (NS) records, extending the "ghost domain window" by up to one cached Time To Live (TTL) value. This manipulation could lead to cache poisoning, potentially causing the Unbound server to serve incorrect or malicious DNS information.
Отчет
This Moderate flaw in Unbound allows a remote attacker to manipulate the DNS cache via a "ghost domain names" attack. An attacker controlling a malicious zone can extend the validity of cached Name Server records, potentially leading to cache poisoning and the provision of incorrect DNS information. The vulnerability is more readily exploitable in non-default configurations where harden-referral-path: yes is enabled, as this setting removes the requirement for a client NS query.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | unbound | Out of support scope | ||
| Red Hat Enterprise Linux 7 | unbound | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | ||
| Red Hat Enterprise Linux 10 | unbound | Fixed | RHSA-2026:36320 | 07.07.2026 |
| Red Hat Enterprise Linux 8 | unbound | Fixed | RHSA-2026:37282 | 09.07.2026 |
| Red Hat Enterprise Linux 9 | unbound | Fixed | RHSA-2026:36777 | 08.07.2026 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202608130832 | Fixed | RHSA-2026:54769 | 18.08.2026 |
| Red Hat Hardened Images | unbound-main-1.25.1-1.hum1 | Fixed | RHSA-2026:20357 | 23.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...
EPSS
7.5 High
CVSS3