INFSA-2025:0837: unbound security update

Information about definition

Identificator: INFSA-2025:0837

Type: security

Release date: 2025-03-05 17:10:11 UTC

Information about package

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Vulnerabilities description

  • CVE-2024-1488

    A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

  • CVE-2024-8508

    A flaw was found in Unbound which can lead to degraded performance and an eventual denial of service when handling replies with very large RRsets that require name compression to be applied. Versions prior to 1.21.1 do not have a hard limit on the number of name compression calculations that Unbound can perform per packet, meaning that if a specially crafted query is passed for the contents of a malicious zone with very large RRsets, Unbound may spend a considerable amount of time applying name compression to downstream replies, locking the CPU until the whole packet has been processed.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-1488
no information 8.0 no information
NIST — CVE-2024-8508
no information 5.3 no information
Critical, important, moderate, low

Updated packages