Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55708

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

A flaw in Unbound's unbound-control utility can omit default-protected zones when initializing local data for a view. This allows queries for protected local names to bypass intended policies and leak to the public DNS, potentially exposing sensitive network information.

Отчет

This is a Low impact flaw in Unbound. A highly privileged user, by using unbound-control to create a view without initial local data, can cause queries for internal network names to be sent to public DNS servers. This bypasses local policy and could lead to the disclosure of internal network information.

Меры по смягчению последствий

Do not run unbound-control view_local_data / view_local_datas on named views that started with no local-data; put local-data (or the RFC 1918 / AS112 / .onion / .localhost local-zones) in unbound.conf so the tree is built at startup with the defaults. If views or remote control are unused, leave control-enable: no and keep the control socket admin-only. Block Unbound from sending those names to the public Internet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10unboundFix deferred
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 7unboundFix deferred
Red Hat Enterprise Linux 8unboundFix deferred
Red Hat Enterprise Linux 9unboundFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Hardened Imagesunbound-main-1.25.2-0.1.hum1FixedRHSA-2026:4358822.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-213
https://bugzilla.redhat.com/show_bug.cgi?id=2506131unbound: Unbound: Information disclosure due to local policy bypass via unbound-control

EPSS

Процентиль: 5%
0.0015
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
2 месяца назад

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

CVSS3: 3.1
nvd
2 месяца назад

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

CVSS3: 3.1
msrc
2 месяца назад

Privacy/configuration issue when adding local data in views through 'unbound-control'

CVSS3: 3.1
debian
2 месяца назад

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_loca ...

CVSS3: 3.1
github
2 месяца назад

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

EPSS

Процентиль: 5%
0.0015
Низкий

3.1 Low

CVSS3