INFSA-2025:8047: unbound security update

Information about definition

Identificator: INFSA-2025:8047

Type: security

Release date: 2025-07-15 19:42:32 UTC

Information about package

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Vulnerabilities description

  • CVE-2024-8508

    A flaw was found in Unbound which can lead to degraded performance and an eventual denial of service when handling replies with very large RRsets that require name compression to be applied. Versions prior to 1.21.1 do not have a hard limit on the number of name compression calculations that Unbound can perform per packet, meaning that if a specially crafted query is passed for the contents of a malicious zone with very large RRsets, Unbound may spend a considerable amount of time applying name compression to downstream replies, locking the CPU until the whole packet has been processed.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-8508
no information 5.3 no information
Critical, important, moderate, low

Updated packages