Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 10 DLA-3371-1 Critical Unbound DoS Issue Resolved

debian lts
Calendar Grey March 29, 2023
Dist Debian Esm H88
Learn ways to secure Debian LTS environments using unbound updates focused on resolving denial-of-service attacks and caching vulnerabilities.
Several security vulnerabilities have been discovered in unbound, a validating, recursive, caching DNS resolver

Summary

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation
Attack) has been discovered in various DNS resolving software. The
NRDelegation Attack works by having a malicious delegation with a
considerable number of non responsive nameservers. The attack starts by
querying a resolver for a record that relies on those unresponsive
nameservers. The attack can cause a resolver to spend a lot of
time/resources resolving records under a malicious delegation point where a
considerable number of unresponsive NS records reside. It can trigger high
CPU usage in some resolver implementations that continually look in the
cache for resolved NS records in that delegation. This can lead to degraded
performance and eventually denial of service in orchestrated attacks.
Unbound does not suffer from high CPU usage, but resources are still needed
for resolving the malicious delegation. Unbound will keep trying to resolve

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: unbound
Version: 1.9.0-2+deb10u3
CVE ID: CVE-2020-28935 CVE-2022-3204 CVE-2022-30698 CVE-2022-30699
Debian Bug: 1016493 977165

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here