REDHAT-BUG-2480125: High severity Nlnet Labs Unbound vulnerability
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NLnet Labs Unboundto a version that resolves this vulnerability.Fixed in 1.25.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 100
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2480125?
The severity of REDHAT-BUG-2480125 is classified as high with a score of 7.
How does REDHAT-BUG-2480125 affect NLnet Labs Unbound?
REDHAT-BUG-2480125 allows an adversary to perform a degradation of service attack by exploiting long lists of incoming EDNS options.
What versions of NLnet Labs Unbound are affected by REDHAT-BUG-2480125?
NLnet Labs Unbound versions up to and including 1.25.0 are affected by REDHAT-BUG-2480125.
How can I mitigate the risks associated with REDHAT-BUG-2480125?
To mitigate the risks of REDHAT-BUG-2480125, it is recommended to update NLnet Labs Unbound to the latest version that addresses this vulnerability.
What type of attack does REDHAT-BUG-2480125 describe?
REDHAT-BUG-2480125 describes a degradation of service attack that can stall Unbound threads during parsing.