CVE-2025-5994: Cache poisoning via the ECS-enabled Rebirthday Attack

Published Jul 16, 2025
·
Updated

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

Affected Software

1 affected component
Nlnet Labs Unbound=

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Unbound to a version that resolves this vulnerability.

    Fixed in 1.23.1
  2. Configuration

    To mitigate the Rebirthday Attack on Unbound compiled with ECS support (--enable-subnet), configure Unbound so it does not send ECS information to upstream name servers—set at least one of the following options used for ECS forwarding to disabled: 'send-client-subnet', 'client-subnet-zone', or 'client-subnet-always-forward'.

    Unbound send-client-subnet / client-subnet-zone / client-subnet-always-forward = disable (do not send ECS to upstream)
  3. Configuration

    For resolvers that support ECS, segregate outgoing queries to accommodate different outgoing ECS information to prevent ECS-enabled Rebirthday Attack cache poisoning.

    DNS resolvers supporting EDNS Client Subnet (ECS) outgoing query segregation by ECS = segregate queries
  4. Configuration

    As a mitigation for affected versions, do not use EDNS Client Subnet (ECS) (i.e., disable ECS support/usage in affected caching resolvers).

    DNS resolvers (general) EDNS Client Subnet (ECS) usage = not using ECS

Event History

Jul 16, 2025
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
RemedyDescriptionWeakness
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-5994?

CVE-2025-5994 is classified as a moderate severity vulnerability affecting caching resolvers that support EDNS Client Subnet.

2

How do I fix CVE-2025-5994?

To mitigate CVE-2025-5994, ensure that your Unbound installation is compiled without EDNS Client Subnet support by avoiding the '--enable-subnet' configuration.

3

Which versions of Unbound are affected by CVE-2025-5994?

CVE-2025-5994 affects any version of Unbound that is compiled with EDNS Client Subnet support enabled.

4

What is a 'Rebirthday Attack' related to CVE-2025-5994?

A 'Rebirthday Attack' is a cache poisoning vulnerability that exploits the EDNS Client Subnet feature in caching resolvers.

5

How can I determine if my Unbound configuration is vulnerable to CVE-2025-5994?

Check your Unbound configuration for the presence of the '--enable-subnet' option and confirm if ECS information is being sent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203