Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55717

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 5.9

Описание

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.

A flaw in Unbound allows a remote attacker controlling a delegated domain to trigger a NULL pointer dereference and crash the daemon. Exploitation occurs when serve-expired: yes and specific response-ip or RPZ rules are configured, resulting in a denial of service.

Отчет

This Moderate severity denial of service flaw in Unbound requires specific configurations, including serve-expired: yes and either response-ip or RPZ CNAME override rules. Exploitation depends on a remote attacker controlling a delegated domain and delaying DNS responses, which limits the immediate impact on typical Red Hat Unbound deployments not utilizing these advanced features.

Меры по смягчению последствий

Ensure serve-expired remains disabled (default), or set serve-expired-client-timeout: 0 to bypass the vulnerable callback path. If serving expired answers is necessary, remove any response-ip CNAME redirect rules and RPZ rpz-cname-override entries. Additionally, use access-control to restrict query access, preventing untrusted clients from triggering the flaw via attacker-controlled names.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10unboundFix deferred
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 7unboundNot affected
Red Hat Enterprise Linux 8unboundFix deferred
Red Hat Enterprise Linux 9unboundFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Hardened Imagesunbound-main-1.25.2-0.1.hum1FixedRHSA-2026:4358822.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2506135unbound: Unbound: Denial of Service via crafted DNS responses with expired records

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
2 месяца назад

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.

CVSS3: 5.9
nvd
2 месяца назад

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.

CVSS3: 5.9
msrc
2 месяца назад

'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash

CVSS3: 5.9
debian
2 месяца назад

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-e ...

CVSS3: 5.9
github
2 месяца назад

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.

5.9 Medium

CVSS3