Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-42944

2 месяца назад

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42944

2 месяца назад

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42944

2 месяца назад

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-42944

2 месяца назад

Heap overflow with multiple NSID, COOKIE, PADDING EDNS options

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42944

2 месяца назад

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0009

20 дней назад

Уязвимость unbound

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7mmq-q3m9-jrv7

2 месяца назад

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:24365

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24365

около 2 месяцев назад

ELSA-2026-24365: unbound security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:24369

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:23231

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24369

около 1 месяца назад

ELSA-2026-24369: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-23231

12 дней назад

ELSA-2026-23231: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21083-1

около 1 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2369-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2281-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-42944

Heap overflow with multiple NSID, COOKIE, PADDING EDNS options

CVSS3: 7.5
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
1%
Низкий
2 месяца назад
redos логотип
ROS-20260713-73-0009

Уязвимость unbound

CVSS3: 7.5
1%
Низкий
20 дней назад
github логотип
GHSA-7mmq-q3m9-jrv7

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.

CVSS3: 7.5
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:24365

Important: unbound security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24365

ELSA-2026-24365: unbound security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:24369

Important: unbound security update

около 2 месяцев назад
rocky логотип
RLSA-2026:23231

Important: unbound security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24369

ELSA-2026-24369: unbound security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-23231

ELSA-2026-23231: unbound security update (IMPORTANT)

12 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21083-1

Security update for unbound

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2369-1

Security update for unbound

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2281-1

Security update for unbound

около 2 месяцев назад

Уязвимостей на страницу