Impact
In Unbound versions 1.13.2 through 1.26.1, a timing issue between the asynchronous resolution of DS/DNSKEY records and the ZONEMD integrity check allows an attacker who can alter zone contents before the check completes to serve or persist tampered DNS records. The flaw arises because the zone file may be written to disk or reloaded while the ZONEMD verification is still pending, enabling the compromised data to be returned until the verification finally succeeds. This results in a loss of DNS data authenticity and integrity.
Affected Systems
NLnet Labs Unbound 1.13.2 to 1.26.1 with zonemd-check enabled on zones located below (but not at) a trust anchor.
Risk and Exploitability
The CVSS score of 4.4 categorizes the vulnerability as medium severity. EPSS data is not available, so the exploitation probability cannot be quantified; the issue is not listed in CISA KEV. The likely attack requires the ability to modify the zone file during startup or to prevent completion of the ZONEMD check, which suggests a relatively narrow attack surface. Nevertheless, affected deployments should consider the risk of serving falsified DNS records until the integrity validation fully completes.
OpenCVE Enrichment