NLnet Labs Unbound是NLnet Labs开源的一个高性能DNS解析器。 NLnet Labs Unbound 1.16.2版本至1.25.0版本存在访问控制错误漏洞,该漏洞源于幽灵域名攻击,可能导致攻击者通过控制幽灵区域并查询易受攻击的Unbound,将缓存过期父端引用NS记录集覆盖为子端顶点NS记录集,从而将幽灵域名窗口延长最多一个配置的缓存TTL值。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | 1.16.2< 1.25.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 1.16.2 ~ 1.25.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33278 | 9.1 CRITICAL | Possible arbitrary code execution during DNSSEC validation |
| CVE-2026-42959 | 8.7 HIGH | Crash during DNSSEC validation of malicious content |
| CVE-2026-42944 | 8.7 HIGH | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options |
| CVE-2026-42534 | 6.9 MEDIUM | Jostle logic bypass degrades resolution performance |
| CVE-2026-44390 | 6.9 MEDIUM | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-41292 | 6.6 MEDIUM | Long list of incoming EDNS options degrades performance |
| CVE-2026-42923 | Degradation of service with unbounded NSEC3 hash calculations | |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | |
| CVE-2026-32792 | Packet of death with DNSCrypt | |
| CVE-2026-44608 | Use after free and crash under special conditions in RPZ code |
No comments yet