Impact
Unbound versions 1.14.0 through 1.25.0 incorrectly calculate the size of EDNS options, allowing a crafted packet that contains multiple NSID, DNS Cookie, or EDNS Padding options to overflow the heap when encoded. This overflow writes Unbound‑controlled data and results in a crash of the server. The flaw does not provide code execution but can be used repeatedly to disrupt service availability for any client that can reach the resolver.
Affected Systems
The vulnerability affects NLnet Labs Unbound DNS resolver. All releases between 1.14.0 and 1.25.0, inclusive, are impacted. The issue is fixed in Unbound 1.25.1 and later releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of 0.00842 (<1%) demonstrates a very low but non‑zero exploitation probability, suggesting the vulnerability will be exploited infrequently. The attack vector is inferred to be remote, as the flaw is caused by queries sent to Unbound over the network. An adversary can trigger the heap overflow by attaching multiple NSID, DNS Cookie, or EDNS Padding options to a query, enabling a crash that results in denial of service. The vulnerability is not listed in the CISA KEV catalog but can be exploited remotely without authentication.
OpenCVE Enrichment
Debian DSA
Ubuntu USN