Debian Unbound vulnerabilities
37 known vulnerabilities affecting debian/unbound.
Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM11LOW18
Vulnerabilities
Page 1 of 2
CVE-2023-50387P3HIGHCVSS 7.5fixed in bind9 1:9.18.24-1 (bookworm)2023
CVE-2023-50387 [HIGH] CVE-2023-50387: bind9 - Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and r...
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must eval
debian
CVE-2023-50868P3HIGHCVSS 7.5fixed in bind9 1:9.18.24-1 (bookworm)2023
CVE-2023-50868 [HIGH] CVE-2023-50868: bind9 - The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276...
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash
debian
CVE-2019-25035P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25035 [CRITICAL] CVE-2019-25035: unbound - Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE...
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (fixed in 1.9.6-1)
debian
CVE-2019-25034P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25034 [CRITICAL] CVE-2019-25034: unbound - Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_orig...
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1
debian
CVE-2019-25042P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25042 [CRITICAL] CVE-2019-25042: unbound - Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdat...
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (fixed
debian
CVE-2019-25032P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25032 [CRITICAL] CVE-2019-25032: unbound - Unbound before 1.9.5 allows an integer overflow in the regional allocator via re...
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (
debian
CVE-2019-25038P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25038 [CRITICAL] CVE-2019-25038: unbound - Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscryp...
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (
debian
CVE-2019-25039P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25039 [CRITICAL] CVE-2019-25039: unbound - Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/...
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (fixe
debian
CVE-2019-25033P3LOWCVSS 9.8fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25033 [CRITICAL] CVE-2019-25033: unbound - Unbound before 1.9.5 allows an integer overflow in the regional allocator via th...
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolv
debian
CVE-2019-18934P3LOWCVSS 7.3fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-18934 [HIGH] CVE-2019-18934: unbound - Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can...
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved
debian
CVE-2025-5994P3HIGHCVSS 8.7fixed in unbound 1.17.1-2+deb12u3 (bookworm)2025
CVE-2025-5994 [HIGH] CVE-2025-5994: unbound - A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been ...
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'cl
debian
CVE-2019-16866P3HIGHCVSS 7.5fixed in unbound 1.9.4-1 (bookworm)2019
CVE-2019-16866 [HIGH] CVE-2019-16866: unbound - Unbound before 1.9.4 accesses uninitialized memory, which allows remote attacker...
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
Scope: local
bookworm: resolved (fixed in 1.9.4-1)
bullseye: resolved (fixed in 1.9.4-1)
forky: resolved (fixed in 1.9.4-1)
sid: resolved (fixed in 1.9.4-1)
trixie: reso
debian
CVE-2024-1931P3LOWCVSS 7.5fixed in unbound 1.19.2-1 (forky)2024
CVE-2024-1931 [HIGH] CVE-2024-1931: unbound - NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a v...
NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size. Before removing all the EDE records however, it wou
debian
CVE-2020-12662P3HIGHCVSS 7.5fixed in unbound 1.10.1-1 (bookworm)2020
CVE-2020-12662 [HIGH] CVE-2020-12662: unbound - Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an...
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed in 1.10.1-1)
sid: resolved (fixed in 1.10.1-1)
trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2019-25041P3LOWCVSS 7.5fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25041 [HIGH] CVE-2019-25041: unbound - Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_...
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (fixed in
debian
CVE-2019-25040P3LOWCVSS 7.5fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25040 [HIGH] CVE-2019-25040: unbound - Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_...
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
forky: resolved (fixed in 1.9
debian
CVE-2024-33655P3HIGHCVSS 7.5fixed in unbound 1.17.1-2+deb12u3 (bookworm)2024
CVE-2024-33655 [HIGH] CVE-2024-33655: unbound - The DNS protocol in RFC 1035 and updates allows remote attackers to cause a deni...
The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.
Scope: local
bookworm: resolved (fixed in 1.17.1-
debian
CVE-2020-12663P3HIGHCVSS 7.5fixed in unbound 1.10.1-1 (bookworm)2020
CVE-2020-12663 [HIGH] CVE-2020-12663: unbound - Unbound before 1.10.1 has an infinite loop via malformed DNS answers received fr...
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed in 1.10.1-1)
sid: resolved (fixed in 1.10.1-1)
trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2022-3204P3HIGHCVSS 7.5fixed in unbound 1.16.3-1 (bookworm)2022
CVE-2022-3204 [HIGH] CVE-2022-3204: unbound - A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) h...
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can
debian
CVE-2019-25037P3LOWCVSS 7.5fixed in unbound 1.9.6-1 (bookworm)2019
CVE-2019-25037 [HIGH] CVE-2019-25037: unbound - Unbound before 1.9.5 allows an assertion failure and denial of service in dname_...
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Scope: local
bookworm: resolved (fixed in 1.9.6-1)
bullseye: resolved (fixed in 1.9.6-1)
for
debian
1 / 2Next →