PT-2022-6740 · Nlnet+10 · Unbound+10
Xiang Li
·
Published
2022-08-01
·
Updated
2024-06-11
·
CVE-2022-30699
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.16.1 and earlier
Description
The issue is related to a novel type of the "ghost domain names" attack, where an Unbound instance is targeted. The attack works by querying Unbound for a rogue domain name when the cached delegation information is about to expire. A rogue nameserver delays the response, causing the cached delegation information to expire. Upon receiving the delayed answer, Unbound overwrites the now expired entries, allowing the rogue delegation information to be ever-updating.
Recommendations
Update to version 1.16.2 or later to fix the issue.
As a temporary workaround, consider restricting access to the Unbound instance to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Unbound