Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unbound | Nov 27, 2019 | Oct 3, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 3, 2019 |
| Debian | — | Upgrade unbound | Oct 17, 2019 | Oct 3, 2019 |
| Freebsd | — | Upgrade unbound | Oct 4, 2019 | Oct 3, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-unboundUpgrade python2-unboundUpgrade unbound-libsUpgrade unbound | Aug 31, 2020 | Oct 3, 2019 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-unboundUpgrade unboundUpgrade unbound-libs | Nov 3, 2020 | Oct 3, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2019 |
| Ubuntu | — | Upgrade libunbound8Upgrade unbound | Oct 9, 2019 | Oct 3, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 3, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub