PT-2024-3663 · Unbound+6 · Unbound+6

Xiang Li

·

Published

2024-05-08

·

Updated

2026-05-19

·

CVE-2024-33655

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Unbound (affected versions not specified)
Description The issue is related to the DNS protocol, which allows remote attackers to cause a denial of service by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst. This can be considered traffic amplification in some cases, also known as the "DNSBomb" issue. The attack works by sending a slow stream of modified DNS requests to DNS servers, which relay the data, increasing the packet size and holding it to then release all at once in a burst of DNS traffic directly at the target. The research group claims to have tested their technique on 10 major DNS programs and 46 public DNS services and was able to launch DNSBomb at a rate of up to 8.7 Gbit/s, with DNS traffic increased up to 20,000 times its original size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:18556
ALSA-2026:18931
ALT-PU-2024-8009
ALT-PU-2024-8011
ALT-PU-2024-8013
ALT-PU-2024-8086
ALT-PU-2024-8131
AZL-42447
AZL-42490
BDU:2024-04004
CVE-2024-33655
DLA-3834-1
DLA-4280-1
DSA-5987-1
MGASA-2024-0203
OESA-2024-2231
OESA-2024-2232
OESA-2024-2233
OESA-2024-2234
OPENSUSE-SU-2024:13944-1
RHSA-2026:18556
RHSA-2026:18931
SUSE-SU-2025:20024-1
USN-6791-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Red Os
Ubuntu
Unbound