In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unbound | Jul 29, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-unbound-debuginfoUpgrade unbound-anchor-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-debuginfoUpgrade unbound-debugsourceUpgrade unbound-utilsUpgrade unbound-anchorUpgrade python3-unboundUpgrade unboundUpgrade unbound-utils-debuginfoUpgrade unbound-develUpgrade unbound-libs | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade unbound | Sep 21, 2026 | Jul 22, 2026 |
| Freebsd | — | Upgrade unbound | Jul 28, 2026 | Jul 25, 2026 |
| Redhat_linux | — | No solution exists | Aug 20, 2026 | Jul 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub