Описание
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending queries with an excessive number of EDNS (Extension Mechanisms for DNS) options. This can cause Unbound threads to be held hostage while parsing and creating internal data structures for these options. Coordinated attacks can lead to resource exhaustion, resulting in a degradation of service or a denial of service (DoS) for legitimate users.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Data Grid 8 | unboundid-ldapsdk | Not affected | ||
| Red Hat Enterprise Linux 6 | unbound | Affected | ||
| Red Hat Enterprise Linux 7 | unbound | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | unboundid-ldapsdk | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8-tech-preview/openstack-unbound | Affected | ||
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-unbound | Affected | ||
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-unbound-rhel9 | Affected | ||
| Red Hat OpenStack Platform 18.0 | rhoso-operators/designate-rhel9-operator | Affected | ||
| Red Hat Enterprise Linux 10 | unbound | Fixed | RHSA-2026:36320 | 07.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to ...
7.5 High
CVSS3