ELA-1567-1 unbound security update
freexian.com·17h
Flag this post
PackageVersionRelated CVEs
unbound
1.9.0-2+deb10u7 (buster)
CVE-2025-11411

Yuxiao Wu, Yunyi Zhang, Baojun Liu and Haixin Duan discovered that unbound, a validating, recursive, and caching DNS resolver, was vulnerable to cache poisoning via NS RRSet injection, which could lead to domain hijack.

Promiscuous NS RRSets that complement DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver’s knowledge of the zone’s name servers. A malicious actor who is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) can poi…

Similar Posts

Loading similar posts...