Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41292

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending queries with an excessive number of EDNS (Extension Mechanisms for DNS) options. This can cause Unbound threads to be held hostage while parsing and creating internal data structures for these options. Coordinated attacks can lead to resource exhaustion, resulting in a degradation of service or a denial of service (DoS) for legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8unboundid-ldapsdkNot affected
Red Hat Enterprise Linux 6unboundAffected
Red Hat Enterprise Linux 7unboundAffected
Red Hat JBoss Enterprise Application Platform Expansion Packunboundid-ldapsdkNot affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8-tech-preview/openstack-unboundAffected
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-unboundAffected
Red Hat OpenStack Platform 18.0rhoso/openstack-unbound-rhel9Affected
Red Hat OpenStack Platform 18.0rhoso-operators/designate-rhel9-operatorAffected
Red Hat Enterprise Linux 10unboundFixedRHSA-2026:3632007.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2480125unbound: Unbound: Denial of Service via excessive EDNS options

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

CVSS3: 7.5
nvd
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).

CVSS3: 7.5
msrc
2 месяца назад

Long list of incoming EDNS options degrades performance

CVSS3: 7.5
debian
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to ...

CVSS3: 7.5
redos
19 дней назад

Уязвимость unbound

7.5 High

CVSS3