PT-2024-39063 · Nlnet+11 · Unbound+11

Toshifumi Sakaguchi

·

Published

2024-10-03

·

Updated

2026-05-20

·

CVE-2024-8508

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: NLnet Labs Unbound versions 1.21.0 and earlier
Description: The issue arises when handling replies with very large RRsets that require name compression. Malicious upstream responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies, leading to degraded performance and potentially denial of service in well-orchestrated attacks. A malicious actor can exploit this by querying Unbound for specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query, it attempts to apply name compression, which was previously an unbounded operation that could lock the CPU until the whole packet was complete.
Recommendations: For NLnet Labs Unbound versions 1.21.0 and earlier, update to version 1.21.1 or later, which introduces a hard limit on the number of name compression calculations it is willing to do per packet, preventing the CPU from being locked for long periods.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:11232
ALSA-2025:0837
ALSA-2025:8047
ALT-PU-2024-13568
ALT-PU-2024-13570
ALT-PU-2024-13810
ALT-PU-2024-14163
ALT-PU-2024-15496
AZL-49915
AZL-49976
BDU:2025-11496
CESA-2025_0837
CVE-2024-8508
DLA-3952-1
DSA-5987-1
INFSA-2024_11232
INFSA-2025_0837
INFSA-2025_8197
MGASA-2024-0333
OESA-2024-2266
OPENSUSE-SU-2024:14391-1
OPENSUSE-SU-2024_3646-1
OPENSUSE-SU-2024_3647-1
RHSA-2024:11170
RHSA-2024:11232
RHSA-2024_11232
RHSA-2025:0837
RHSA-2025:8047
RHSA-2025:8197
RHSA-2025_0837
RHSA-2025_8197
RLSA-2024:11232
RLSA-2025:0837
RUSTSEC-2026-0119
SUSE-SU-2024:3646-1
SUSE-SU-2024:3647-1
SUSE-SU-2024_3646-1
SUSE-SU-2024_3647-1
SUSE-SU-2025:20126-1
SUSE-SU-2025:20359-1
USN-7080-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Unbound