Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-42959

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42959

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42959

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-42959

2 месяца назад

Crash during DNSSEC validation of malicious content

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42959

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a denial of ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0010

20 дней назад

Уязвимость unbound

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5jp8-75xr-qrmf

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:24365

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24365

около 2 месяцев назад

ELSA-2026-24365: unbound security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:24369

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:23231

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24369

около 1 месяца назад

ELSA-2026-24369: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-23231

12 дней назад

ELSA-2026-23231: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21083-1

около 1 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2369-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2281-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42959

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-42959

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-42959

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-42959

Crash during DNSSEC validation of malicious content

CVSS3: 7.5
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-42959

NLnet Labs Unbound up to and including version 1.25.0 has a denial of ...

CVSS3: 7.5
1%
Низкий
2 месяца назад
redos логотип
ROS-20260713-73-0010

Уязвимость unbound

CVSS3: 7.5
1%
Низкий
20 дней назад
github логотип
GHSA-5jp8-75xr-qrmf

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.

CVSS3: 7.5
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:24365

Important: unbound security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24365

ELSA-2026-24365: unbound security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:24369

Important: unbound security update

около 2 месяцев назад
rocky логотип
RLSA-2026:23231

Important: unbound security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24369

ELSA-2026-24369: unbound security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-23231

ELSA-2026-23231: unbound security update (IMPORTANT)

12 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21083-1

Security update for unbound

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2369-1

Security update for unbound

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2281-1

Security update for unbound

около 2 месяцев назад

Уязвимостей на страницу