NLnet Labs Unbound是NLnet Labs开源的一个高性能DNS解析器。 NLnet Labs Unbound 1.6.2版本至1.25.0版本存在缓冲区错误漏洞,该漏洞源于DNSCrypt数据包读取过程下溢可能导致堆溢出。恶意攻击者可利用单个恶意DNSCrypt查询触发漏洞,其解密明文完全由0x00字节组成且不包含预期的0x80标记,导致Unbound读取超出必要字节。基于底层内存分配器和内存布局,可能导致堆溢出并引发崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | 1.6.2< 1.25.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 1.6.2 ~ 1.25.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33278 | 9.1 CRITICAL | Possible arbitrary code execution during DNSSEC validation |
| CVE-2026-42534 | 6.9 MEDIUM | Jostle logic bypass degrades resolution performance |
| CVE-2026-44390 | 6.9 MEDIUM | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-41292 | 6.6 MEDIUM | Long list of incoming EDNS options degrades performance |
| CVE-2026-42959 | Crash during DNSSEC validation of malicious content | |
| CVE-2026-42923 | Degradation of service with unbounded NSEC3 hash calculations | |
| CVE-2026-42944 | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options | |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | |
| CVE-2026-40622 | Another 'ghost domain names' attack variant | |
| CVE-2026-44608 | Use after free and crash under special conditions in RPZ code |
No comments yet