NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.
CVSS Details
- CVSS 4.0 Base Score: 5.7 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber)
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade python3-unboundUpgrade unbound-anchorUpgrade unboundUpgrade unbound-libsUpgrade unbound-utilsUpgrade unbound-develUpgrade python2-unboundUpgrade unbound-debuginfo | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-utilsUpgrade python3-unboundUpgrade python3-unbound-debuginfoUpgrade unbound-utils-debuginfoUpgrade unbound-debugsourceUpgrade unbound-anchorUpgrade unbound-libs-debuginfoUpgrade unboundUpgrade unbound-libsUpgrade unbound-anchor-debuginfoUpgrade unbound-develUpgrade unbound-debuginfo | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade unbound | Jun 15, 2026 | Jun 10, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 20, 2026 |
| Ubuntu | — | Upgrade libunbound8Upgrade unbound (Ubuntu Pro)Upgrade unboundUpgrade libunbound8 (Ubuntu Pro)Upgrade libunbound2 (Ubuntu Pro) | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub