Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42534

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended.

A flaw was found in Unbound. An adversary who can query a vulnerable Unbound instance and control a slow or malicious domain name server can exploit a vulnerability in the jostle logic. This flaw allows retransmitted queries to renew the age of slow-running queries, preventing them from being identified as aged and replaced. This can degrade Unbound's resolution performance, potentially leading to a denial of resolution service through coordinated attacks.

Отчет

This flaw is rated as Important. An attacker controlling a malicious DNS server could exploit a vulnerability in Unbound's jostle logic, leading to degraded resolution performance and a potential denial of service. This occurs because retransmitted queries can incorrectly renew the age of slow-running queries, preventing their proper replacement.

Меры по смягчению последствий

To mitigate the risk of denial of resolution service, restrict Unbound's network exposure. Configure Unbound to only accept queries from trusted internal networks and to forward its own queries exclusively to trusted, well-maintained upstream DNS servers. This reduces the opportunity for an adversary to interact with or act as a malicious upstream for the vulnerable Unbound instance. After modifying Unbound's configuration, a service restart is required for changes to take effect. This may temporarily interrupt DNS resolution services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6unboundAffected
Red Hat Enterprise Linux 7unboundAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10unboundFixedRHSA-2026:3632007.07.2026
Red Hat Enterprise Linux 8unboundFixedRHSA-2026:3728209.07.2026
Red Hat Enterprise Linux 9unboundFixedRHSA-2026:3677708.07.2026
Red Hat Hardened Imagesunbound-main-1.25.1-2.hum1FixedRHSA-2026:2401307.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-911
https://bugzilla.redhat.com/show_bug.cgi?id=2480131unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort...

CVSS3: 5.3
nvd
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. C

CVSS3: 5.3
msrc
2 месяца назад

Jostle logic bypass degrades resolution performance

CVSS3: 5.3
debian
2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabil ...

CVSS3: 5.3
redos
19 дней назад

Уязвимость unbound

7.5 High

CVSS3