NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-unboundUpgrade unbound-develUpgrade unbound-libsUpgrade unbound-dracutUpgrade unbound | Aug 2, 2026 | Jul 8, 2026 |
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade unbound-debuginfoUpgrade python2-unboundUpgrade unbound-libsUpgrade unboundUpgrade unbound-utilsUpgrade unbound-develUpgrade unbound-anchorUpgrade python3-unbound | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-anchor-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-anchorUpgrade python3-unboundUpgrade unboundUpgrade unbound-utilsUpgrade unbound-debuginfoUpgrade unbound-debugsourceUpgrade unbound-develUpgrade unbound-utils-debuginfoUpgrade unbound-libsUpgrade python3-unbound-debuginfo | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Aug 10, 2026 | Aug 7, 2026 |
| Freebsd | — | Upgrade unboundUpgrade FreeBSD | Jun 15, 2026 | Jun 10, 2026 |
| Redhat_linux | — | Upgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade python3-unboundUpgrade unbound-utils-debuginfoUpgrade unbound-anchor-debuginfoUpgrade python3-unbound-debuginfoUpgrade unbound-debugsourceUpgrade unboundUpgrade unbound-dracutUpgrade unbound-debuginfoNo solution existsUpgrade unbound-anchorUpgrade unbound-develUpgrade unbound-libs | Jul 17, 2026 | May 20, 2026 |
| Rocky_linux | — | Upgrade unbound-dracutUpgrade python3-unboundUpgrade unbound-libsUpgrade unbound-debuginfoUpgrade unboundUpgrade python3-unbound-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-debugsourceUpgrade unbound-devel | Jul 30, 2026 | Jul 28, 2026 |
| Ubuntu | — | Upgrade libunbound8Upgrade unbound | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub