Impact
Libunbound applications that set a non‑zero 'unwanted‑reply‑threshold' value can be brought down after that number of incorrect‑ID UDP replies is received. The vulnerable library calls a cleanup routine that is not on the function‑call allow list, causing a fatal exit of libunbound and termination of the embedding process. The resulting effect is a service disruption to the affected application, classified as a denial of service.
Affected Systems
NLnet Labs Unbound binaries that link to libunbound, for all releases up to and including 1.25.1, when configured with any non‑zero 'unwanted‑reply‑threshold'. The core Unbound daemon is not affected because its cleanup routine is already in the allow list.
Risk and Exploitability
With a CVSS score of 5.9 the vulnerability is of moderate severity, and an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. An attacker could trigger it by sending sufficient bogus‑ID UDP replies from a rogue authoritative server to a client using libunbound, provided the client has a non‑zero threshold set. The exploit can be performed remotely with crafted network traffic, but would require the victim to be actively using libunbound with the threshold enabled.
OpenCVE Enrichment