Impact
In Unbound versions 1.20.0 through 1.25.1, a configuration that enables serve‑expired with serve‑expired‑client‑timeout greater than discard‑timeout results in a counter that is never decremented when a client reply is discarded. The counter can overflow, causing duplicate in‑flight queries from new clients to be silently dropped. An attacker can trigger this by directing the resolver to handle an authoritative zone that responds slowly, forcing the counter past its threshold and degrading DNS resolution service.
Affected Systems
The vulnerability affects NLnet Labs Unbound running any version from 1.20.0 to 1.25.1. The issuing patch is included in version 1.25.2 and later.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is < 1%. The vulnerability is not listed in CISA's KEV. Exploitation requires a server to be mis‑configured with the described timeout settings; an attacker then exploits the service by sending queries that reference a slow‑responding authoritative zone. Because the issue is limited to servers with those settings, the risk is lower for correctly configured installations but can still lead to a denial of service for affected deployments.
OpenCVE Enrichment