-
Notifications
You must be signed in to change notification settings - Fork 123
Open
Labels
securityTopic/issue involves a security issue/fixedTopic/issue involves a security issue/fixed
Description
Affected package (and version)
unbound (1.19.2+icannbundle20210902-1)
CVE ID(s)
CVE-2024-33655, CVE-2024-33655, CVE-2025-5994
Severity
High
Other security advisory ID(s)
- Upstream security advisories: https://nlnetlabs.nl/projects/unbound/security-advisories/
Description/References
- CVE-2024-33655: Low risk, possibility of participation in the pulsing DoS amplification attack.
- CVE-2024-33655: Medium risk, possibility of DoS in orchestrated attacks.
- CVE-2025-5994: High risk, cache poisoning vulnerability named "rebirthday attack" in caching resolvers that support EDNS Client Subnet (ECS).
Patch(es)/Solution(s)
N/A
Metadata
Metadata
Assignees
Labels
securityTopic/issue involves a security issue/fixedTopic/issue involves a security issue/fixed