Количество 20
Количество 20
GHSA-m3vq-fgh9-hq65
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
CVE-2026-40622
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
CVE-2026-40622
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
CVE-2026-40622
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
CVE-2026-40622
Another 'ghost domain names' attack variant
CVE-2026-40622
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...
ROS-20260713-80-0011
Уязвимость unbound
ROS-20260713-73-0011
Уязвимость unbound
BDU:2026-12030
Уязвимость DNS-сервера unbound, связанная с недостатками в механизме подтверждения источника данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
RLSA-2026:37282
Important: unbound security update
RLSA-2026:36777
Important: unbound security update
RLSA-2026:36320
Important: unbound security update
ELSA-2026-37282
ELSA-2026-37282: unbound security update (IMPORTANT)
ELSA-2026-36777
ELSA-2026-36777: unbound security update (IMPORTANT)
ELSA-2026-36320
ELSA-2026-36320: unbound security update (IMPORTANT)
openSUSE-SU-2026:21083-1
Security update for unbound
SUSE-SU-2026:2369-1
Security update for unbound
SUSE-SU-2026:2281-1
Security update for unbound
SUSE-SU-2026:3885-1
Security update for unbound
openSUSE-SU-2026:21550-1
Security update for unbound
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-m3vq-fgh9-hq65 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-40622 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-40622 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-40622 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-40622 Another 'ghost domain names' attack variant | 0% Низкий | 4 месяца назад | ||
CVE-2026-40622 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260713-80-0011 Уязвимость unbound | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
ROS-20260713-73-0011 Уязвимость unbound | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
BDU:2026-12030 Уязвимость DNS-сервера unbound, связанная с недостатками в механизме подтверждения источника данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
RLSA-2026:37282 Important: unbound security update | около 2 месяцев назад | |||
RLSA-2026:36777 Important: unbound security update | около 2 месяцев назад | |||
RLSA-2026:36320 Important: unbound security update | около 2 месяцев назад | |||
ELSA-2026-37282 ELSA-2026-37282: unbound security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-36777 ELSA-2026-36777: unbound security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-36320 ELSA-2026-36320: unbound security update (IMPORTANT) | 2 месяца назад | |||
openSUSE-SU-2026:21083-1 Security update for unbound | 3 месяца назад | |||
SUSE-SU-2026:2369-1 Security update for unbound | 3 месяца назад | |||
SUSE-SU-2026:2281-1 Security update for unbound | 4 месяца назад | |||
SUSE-SU-2026:3885-1 Security update for unbound | 22 дня назад | |||
openSUSE-SU-2026:21550-1 Security update for unbound | около 1 месяца назад |
Уязвимостей на страницу