CVE-2024-8508

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 3, 2024
Updated: Dec 17, 2024
CWE ID 606
CWE ID 1284

Summary

CVE-2024-8508 is a vulnerability affecting NLnet Labs Unbound DNS resolver up to version 1.21.0. Malicious actors can exploit this issue by sending very large RRsets to Unbound, causing it to spend extensive time on name compression. This can lead to performance degradation and even denial of service in targeted attacks. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations per packet to mitigate this risk. Large packets will result in semi-compressed or truncated responses to prevent prolonged CPU locking. This update should not impact normal DNS traffic.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • NLNet Labs Unbound
  • Debian

Affected Vendors

  • Debian
  • NLnet Labs