Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-77955

Опубликовано: 17 сент. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.4

Описание

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

1.26.1-1

Показывать по

EPSS

Процентиль: 3%
0.00128
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
1 день назад

A flaw was found in Unbound. This vulnerability affects ZONEMD configured zones that are located below a trust anchor, allowing tampered zone contents to be served or stored to disk before integrity checks are completed. This occurs due to the asynchronous resolution of DS/DNSKEY records, which creates a window where the integrity check is not yet finalized. Consequently, if a zone file is written to disk while the ZONEMD check has not yet completed or failed, the compromised data can be reloaded on startup and remain available until ZONEMD verification concludes again, potentially leading to the serving of incorrect DNS information.

CVSS3: 4.4
nvd
1 день назад

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

CVSS3: 4.4
debian
1 день назад

Описание отсутствует

CVSS3: 4.4
github
1 день назад

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.

EPSS

Процентиль: 3%
0.00128
Низкий

4.4 Medium

CVSS3