NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met…
NLnet Labs·CWE-413·Published 2026-05-20
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.
NLnet Labs Unbound 1.14.0 hasta e incluyendo la versión 1.25.0 tiene una vulnerabilidad de inconsistencia de bloqueo que, cuando se cumplen ciertas condiciones (multihilo, recarga de RPZ XFR, zona RPZ con disparadores 'rpz-nsip'/'rpz-nsdname'), podría resultar en un uso después de liberación de la pila y un fallo eventual. Un adversario puede explotar la vulnerabilidad si primero se cumplen las condiciones en un Unbound vulnerable, es decir, multihilo, una zona RPZ con disparadores 'rpz-nsip'/'rpz-nsdname' y un XFR en curso para esa zona RPZ. Los archivos RPZ locales no disparan la vulnerabilidad. Si el momento es el adecuado y un XFR ocurre al mismo tiempo que otro hilo necesita leer esa zona RPZ, el lector podría no mantener el bloqueo el tiempo suficiente y el hilo que aplica el XFR podría liberar objetos que el lector está a punto de recorrer, causando el uso después de liberación. Unbound 1.25.1 contiene un parche con una corrección para el código de bloqueo.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 5.9 | 2.2 | 3.6 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 4.0 | Primary | cve.org | 4.6 | — | — | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber |
| 4.0 | Secondary | NVD | 4.6 | — | — | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber |