Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40622

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

A flaw was found in NLnet Labs Unbound. A remote attacker, by controlling a malicious domain (a "ghost zone") and querying a vulnerable Unbound server, could exploit a vulnerability related to "ghost domain names" attacks. This could allow the attacker to overwrite cached Name Server (NS) records, extending the "ghost domain window" by up to one cached Time To Live (TTL) value. This manipulation could lead to cache poisoning, potentially causing the Unbound server to serve incorrect or malicious DNS information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundUnder investigation
Red Hat Enterprise Linux 7unboundUnder investigation
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10unboundFixedRHSA-2026:3632007.07.2026
Red Hat Enterprise Linux 8unboundFixedRHSA-2026:3728209.07.2026
Red Hat Enterprise Linux 9unboundFixedRHSA-2026:3677708.07.2026
Red Hat Hardened Imagesunbound-main-1.25.1-1.hum1FixedRHSA-2026:2035723.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2480127unbound: Unbound: Cache manipulation via 'ghost domain names' attack

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
nvd
2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

msrc
2 месяца назад

Another 'ghost domain names' attack variant

CVSS3: 7.5
debian
2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
redos
19 дней назад

Уязвимость unbound

7.5 High

CVSS3