Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40622

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

A flaw was found in NLnet Labs Unbound. A remote attacker, by controlling a malicious domain (a "ghost zone") and querying a vulnerable Unbound server, could exploit a vulnerability related to "ghost domain names" attacks. This could allow the attacker to overwrite cached Name Server (NS) records, extending the "ghost domain window" by up to one cached Time To Live (TTL) value. This manipulation could lead to cache poisoning, potentially causing the Unbound server to serve incorrect or malicious DNS information.

Отчет

This Moderate flaw in Unbound allows a remote attacker to manipulate the DNS cache via a "ghost domain names" attack. An attacker controlling a malicious zone can extend the validity of cached Name Server records, potentially leading to cache poisoning and the provision of incorrect DNS information. The vulnerability is more readily exploitable in non-default configurations where harden-referral-path: yes is enabled, as this setting removes the requirement for a client NS query.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundOut of support scope
Red Hat Enterprise Linux 7unboundAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat Enterprise Linux 10unboundFixedRHSA-2026:3632007.07.2026
Red Hat Enterprise Linux 8unboundFixedRHSA-2026:3728209.07.2026
Red Hat Enterprise Linux 9unboundFixedRHSA-2026:3677708.07.2026
Red Hat OpenShift Container Platform 4.22rhcos-4.22.9.8.202608130832FixedRHSA-2026:5476918.08.2026
Red Hat Hardened Imagesunbound-main-1.25.1-1.hum1FixedRHSA-2026:2035723.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2480127unbound: Unbound: Cache manipulation via 'ghost domain names' attack

EPSS

Процентиль: 3%
0.00136
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
nvd
4 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

msrc
4 месяца назад

Another 'ghost domain names' attack variant

CVSS3: 7.5
debian
4 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
redos
2 месяца назад

Уязвимость unbound

EPSS

Процентиль: 3%
0.00136
Низкий

7.5 High

CVSS3