NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section.…
NLnet Labs·CWE-349·Published 2026-05-20
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.
NLnet Labs Unbound hasta e incluyendo la versión 1.25.0 es vulnerable a envenenamiento a través de registros promiscuos para la sección de autoridad. Los RRSets promiscuos que complementan las respuestas DNS en la sección de autoridad pueden usarse para engañar a Unbound para que almacene en caché dichos registros. Si un adversario es capaz de adjuntar dichos registros en una respuesta (es decir, paquete falsificado, ataque de fragmentación) podría envenenar la caché de Unbound. Un actor malicioso puede exploit el posible efecto de envenenamiento inyectando RRSets distintos de NS que también estén acompañados de registros de dirección en una respuesta, por ejemplo MX. Esto podría lograrse intentando falsificar un paquete de respuesta o mediante ataques de fragmentación. Unbound aceptaría entonces los registros de dirección relativos en la sección adicional y los almacenaría en caché si el RRSet de autoridad tiene suficiente confianza en este punto, es decir, datos en zona para el punto de delegación. Unbound 1.25.1 contiene un parche con una corrección que ignora los registros de dirección de la sección adicional si no son explícitamente relevantes solo para los registros NS de autoridad, mitigando el posible efecto de envenenamiento. Esta es una corrección complementaria a CVE-2025-11411.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 10.0 | 3.9 | 5.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H |
| 4.0 | Primary | cve.org | 5.7 | — | — | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/U:Amber |
| 4.0 | Secondary | NVD | 5.7 | — | — | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber |