Impact
In NLnet Labs Unbound versions 1.16.2 through 1.25.1, a flaw exists that allows an attacker who controls a ghost zone to extend the period during which that zone remains reachable. By sending or causing the server to send an A/AAAA query, Unbound overwrites a stale parent‑side glue RRset and refreshes its cached TTL to the configured cache‑max‑TTL. The result is that the ghost domain window can be prolonged by that TTL amount. Although the exploit does not immediately grant control, the extra time can be used to execute a takeover or denial‑of‑service attack. The vulnerability is recorded as CWE‑354 and CWE‑672.
Affected Systems
The affected product is NLnet Labs Unbound. All releases between 1.16.2 and 1.25.1, inclusive, are vulnerable. Version 1.25.2 and later contain the fix. Public DNS servers that answer queries for this software and are reachable to attackers, especially those with the harden‑referral‑path option enabled, are at risk.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity. The EPSS score is <1%, implying a very low probability of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. Exploitation requires an attacker to control a ghost zone and to trigger a client A/AAAA query, or to rely on the automatic query performed when harden‑referral‑path is enabled. Successful exploitation only extends the ghost domain window by the cache‑max‑TTL value; it does not give immediate control over the zone or the server.
OpenCVE Enrichment