USN-7080-1: Unbound vulnerability
USN-7080-1: Unbound vulnerability
22 October 2024
Unbound could be made to stop responding if it received specially crafted DNS traffic.
Releases
Ubuntu 24.10 Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS Ubuntu 18.04 ESM Ubuntu 16.04 ESM Ubuntu 14.04 ESM
Packages
unbound - validating, recursive, caching DNS resolver
Details
Toshifumi Sakaguchi discovered that Unbound incorrectly handled name
compression for large RRsets, which could lead to excessive CPU usage.
An attacker could potentially use this issue to cause a denial of service
by sending specially crafted DNS responses.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
- libunbound8 - 1.20.0-1ubuntu2.1
- unbound - 1.20.0-1ubuntu2.1
Ubuntu 24.04 - libunbound8 - 1.19.2-1ubuntu3.3
- unbound - 1.19.2-1ubuntu3.3

