Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55990

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').

A flaw was found in Unbound when configured with DNSCrypt support. An unauthenticated remote attacker could exploit a faulty configuration, where an imbalance between DNSCrypt provider certificate and secret key files leads to memory corruption. By sending a specially crafted network request, the attacker can cause a garbage dereference, leading to a server crash and a denial of service (DoS).

Отчет

This Moderate flaw in Unbound can lead to a denial of service if the DNSCrypt feature is enabled and misconfigured. Exploitation requires Unbound to be compiled with DNSCrypt support, which is not a default setting in Red Hat products, and a specific mismatch between DNSCrypt provider certificate and secret key files. An unauthenticated attacker could then send a crafted UDP packet to trigger a server crash.

Меры по смягчению последствий

To mitigate this issue, ensure that Unbound is not compiled with DNSCrypt support if the feature is not required. If DNSCrypt support is enabled, verify that the number of 'dnscrypt-provider-cert:' files precisely matches the number of 'dnscrypt-secret-key:' files in the Unbound configuration to prevent the faulty configuration that leads to a denial of service. Restart the Unbound service after any configuration changes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10unboundFix deferred
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 7unboundNot affected
Red Hat Enterprise Linux 8unboundFix deferred
Red Hat Enterprise Linux 9unboundFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesunbound-main-1.25.2-0.1.hum1FixedRHSA-2026:4358822.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2506148unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration

EPSS

Процентиль: 17%
0.00257
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
11 дней назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').

CVSS3: 5.9
nvd
11 дней назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').

CVSS3: 5.9
msrc
11 дней назад

Packet of death for a DNSCrypt misconfigured Unbound

CVSS3: 5.9
debian
11 дней назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnsc ...

CVSS3: 5.9
github
11 дней назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').

EPSS

Процентиль: 17%
0.00257
Низкий

5.9 Medium

CVSS3