USN-7080-1: Unbound vulnerability
Toshifumi Sakaguchi discovered that Unbound incorrectly handled name compression for large RRsets, which could lead to excessive CPU usage. An attacker could potentially use this issue to cause a denial of service by sending specially crafted DNS responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7080-1?
USN-7080-1 has a high severity level due to its potential to cause denial of service.
How do I fix USN-7080-1?
To fix USN-7080-1, update the Unbound and libunbound8 packages to their recommended versions for your Ubuntu release.
What systems are affected by USN-7080-1?
USN-7080-1 affects multiple Ubuntu versions, including 14.04, 16.04, 18.04, 20.04, 22.04, and 24.04.
Can USN-7080-1 be exploited remotely?
Yes, USN-7080-1 can be exploited remotely by an attacker through specially crafted DNS responses.
What are the recommended package versions to mitigate USN-7080-1?
The recommended package versions to mitigate USN-7080-1 are libunbound8 version 1.20.0-1ubuntu2.1 for 24.10 and appropriate versions for other affected releases.