PT-2022-6740 · Nlnet+10 · Unbound+10

Xiang Li

·

Published

2022-08-01

·

Updated

2024-06-11

·

CVE-2022-30699

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.16.1 and earlier
Description The issue is related to a novel type of the "ghost domain names" attack, where an Unbound instance is targeted. The attack works by querying Unbound for a rogue domain name when the cached delegation information is about to expire. A rogue nameserver delays the response, causing the cached delegation information to expire. Upon receiving the delayed answer, Unbound overwrites the now expired entries, allowing the rogue delegation information to be ever-updating.
Recommendations Update to version 1.16.2 or later to fix the issue. As a temporary workaround, consider restricting access to the Unbound instance to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7622
ALSA-2022:8062
ALT-PU-2022-2656
ALT-PU-2022-2684
ALT-PU-2022-2700
ALT-PU-2023-7205
AZL-10453
BDU:2023-03845
CESA-2022_7622
CVE-2022-30699
DLA-3371-1
MGASA-2022-0303
OESA-2022-1836
RHSA-2022:7622
RHSA-2022:8062
RHSA-2022_7622
RHSA-2022_8062
RHSA-2024:2045
RLSA-2022:7622
RLSA-2022:8062
SUSE-SU-2024:1923-1
SUSE-SU-2024:1991-1
SUSE-SU-2024:1991-2
USN-5569-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Unbound