CVE-2024-8508
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-8508 is a vulnerability affecting NLnet Labs Unbound DNS resolver up to version 1.21.0. Malicious actors can exploit this issue by sending very large RRsets to Unbound, causing it to spend extensive time on name compression. This can lead to performance degradation and even denial of service in targeted attacks. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations per packet to mitigate this risk. Large packets will result in semi-compressed or truncated responses to prevent prolonged CPU locking. This update should not impact normal DNS traffic.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- NLNet Labs Unbound
- Debian
Affected Vendors
- Debian
- NLnet Labs