Description:
Several multi-vendor cache poisoning vulnerabilities have been
discovered in caching resolvers for non-DNSSEC protected data.
Unbound is vulnerable for some of these cases that could lead to
domain hijacking (CVE-2025-11411).
- https://bugs.mageia.org/show_bug.cgi?id=34700
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt
- https://www.cve.org/CVERecord?id=CVE-2025-11411
- 9/core/unbound-1.24.1-1.mga9
Get the latest Linux and open source security news straight to your inbox.