=========================================================================Ubuntu Security Notice USN-5732-1
November 17, 2022

unbound vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Unbound could be made to stop responding if it received specially crafted
network traffic.

Software Description:
- unbound: validating, recursive, caching DNS resolver

Details:

It was discovered that Unbound incorrectly handled delegations with a large
number of non-responsive nameservers. A remote attacker could possibly use
this issue to cause Unbound to consume resources, leading to a denial of
service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   libunbound8                     1.16.2-1ubuntu0.1
   unbound                         1.16.2-1ubuntu0.1

Ubuntu 22.04 LTS:
   libunbound8                     1.13.1-1ubuntu5.3
   unbound                         1.13.1-1ubuntu5.3

Ubuntu 20.04 LTS:
   libunbound8                     1.9.4-2ubuntu1.4
   unbound                         1.9.4-2ubuntu1.4

Ubuntu 18.04 LTS:
   libunbound2                     1.6.7-1ubuntu2.6
   unbound                         1.6.7-1ubuntu2.6

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5732-1
   CVE-2022-3204

Package Information:
   https://launchpad.net/ubuntu/+source/unbound/1.16.2-1ubuntu0.1
   https://launchpad.net/ubuntu/+source/unbound/1.13.1-1ubuntu5.3
   https://launchpad.net/ubuntu/+source/unbound/1.9.4-2ubuntu1.4
   https://launchpad.net/ubuntu/+source/unbound/1.6.7-1ubuntu2.6

Ubuntu 5732-1: Unbound vulnerability

November 17, 2022
Unbound could be made to stop responding if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libunbound8 1.16.2-1ubuntu0.1 unbound 1.16.2-1ubuntu0.1 Ubuntu 22.04 LTS: libunbound8 1.13.1-1ubuntu5.3 unbound 1.13.1-1ubuntu5.3 Ubuntu 20.04 LTS: libunbound8 1.9.4-2ubuntu1.4 unbound 1.9.4-2ubuntu1.4 Ubuntu 18.04 LTS: libunbound2 1.6.7-1ubuntu2.6 unbound 1.6.7-1ubuntu2.6 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5732-1

CVE-2022-3204

Severity
November 17, 2022

Package Information

https://launchpad.net/ubuntu/+source/unbound/1.16.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/unbound/1.13.1-1ubuntu5.3 https://launchpad.net/ubuntu/+source/unbound/1.9.4-2ubuntu1.4 https://launchpad.net/ubuntu/+source/unbound/1.6.7-1ubuntu2.6

Related News