Impact
In Unbound versions 1.13.2 through 1.26.1, the timing between asynchronous resolution of DS/DNSKEY records and the ZONEMD integrity check can allow an attacker who can alter zone contents before the check completes to serve or persist tampered DNS records. The flaw arises because the zone file may be written to disk or reloaded while the ZONEMD verification is still pending, enabling the compromised data to be returned until verification finally succeeds. This results in a loss of DNS data authenticity and integrity.
Affected Systems
NLnet Labs Unbound 1.13.2 to 1.26.1 with zonemd-check enabled on zones located below (but not at) a trust anchor.
Risk and Exploitability
The CVSS score of 4.4 indicates medium severity. The EPSS score of < 1% indicates a very low but non-zero exploitation probability. The vulnerability is not listed in CISA KEV. This flaw requires an attacker to modify zone content before the ZONEMD check completes or to prevent the check from finishing, which suggests a narrow attack surface; however, affected deployments should monitor for this timing window and the persistence of tampered data until validation succeeds.
OpenCVE Enrichment
Debian DSA