Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-8508— Unbounded name compression could lead to Denial of Service

Quick assessment

Affected
NLnet Labs Unbound
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NLnet Unbound是荷兰NLnet团队的一款开源DNS服务器。 NLnet Unbound 1.21.0及之前版本存在安全漏洞,该漏洞源于处理包含非常大的RRsets的回复时所需执行的名称压缩操作,可能导致性能下降或服务拒绝。

CVSS 5.3 · Medium EPSS 0.80% · P54
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-8508

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unbounded name compression could lead to Denial of Service
Source: CVE Program / CVE List V5
Vulnerability Description
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. The vulnerability can be exploited by a malicious actor querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations it is willing to do per packet. Packets that need more compression will result in semi-compressed packets or truncated packets, even on TCP for huge messages, to avoid locking the CPU for long. This change should not affect normal DNS traffic.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
循环条件输入未经检查
Source: CVE Program / CVE List V5
Vulnerability Title
NLnet Unbound 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NLnet Unbound是荷兰NLnet团队的一款开源DNS服务器。 NLnet Unbound 1.21.0及之前版本存在安全漏洞,该漏洞源于处理包含非常大的RRsets的回复时所需执行的名称压缩操作,可能导致性能下降或服务拒绝。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
NLnet Labs Unbound 0 ~ 1.21.0 -

II. Public POCs for CVE-2024-8508

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-8508

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-8508

No comments yet


Leave a comment