CVE-2020-10772: High severity nlnetlabs Unbound vulnerability
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.
Other sources
The fix for CVE-2020-12662 as shipped in Red Hat Enterprise Linux 7 (with version 1.6.6-4.el78 of Unbound delivered with https://access.redhat.com/errata/RHSA-2020:2414) is not complete and it still allows amplification of an incoming query into a bigger number of queries directed to a target. This issue is about the incomplete fix for CVE-2020-12662 and it does not affect upstream versions of unbound.
For more details about the original issue, refer to bug 1837597.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10772?
CVE-2020-10772 is a vulnerability in Unbound, a DNS resolver, that allows for amplification of incoming queries directed at a target.
What versions of Unbound are affected by CVE-2020-10772?
Versions 1.6.6-5 of Unbound are affected by CVE-2020-10772.
What is the severity of CVE-2020-10772?
CVE-2020-10772 has a severity rating of 7.5 (high).
How can CVE-2020-10772 be exploited?
CVE-2020-10772 can be exploited by sending a specially crafted query to a vulnerable Unbound server, resulting in amplification of the query and redirecting a large number of queries to a target.
How can I fix CVE-2020-10772?
To fix CVE-2020-10772, upgrade to version 1.6.6-5.el7_8 or later of Unbound.