Bug 2303461 - CVE-2024-43167 unbound: NULL Pointer Dereference in Unbound [fedora-all]
Summary: CVE-2024-43167 unbound: NULL Pointer Dereference in Unbound [fedora-all]
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: unbound
Version: 40
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Petr Menšík
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["37d96366-f860-4d3b-aff7-2...
Depends On: 2305092 2316313
Blocks: 2303456
TreeView+ depends on / blocked
 
Reported: 2024-08-07 13:45 UTC by Abhishek Raj
Modified: 2024-10-19 01:18 UTC (History)
3 users (show)

Fixed In Version: unbound-1.21.1-3.fc40 unbound-1.21.1-1.fc41 unbound-1.21.1-3.fc39
Clone Of:
Environment:
Last Closed: 2024-10-06 02:11:44 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github NLnetLabs unbound issues 1072 0 None closed Null pointer dereference issue in function ub_ctx_set_fwd of file libunbound/libunbound.c 2024-10-04 10:08:05 UTC
Github NLnetLabs unbound pull 1073 0 None Merged fix null pointer dereference issue in function ub_ctx_set_fwd 2024-10-04 10:08:05 UTC

Description Abhishek Raj 2024-08-07 13:45:15 UTC
More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2303456

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Petr Menšík 2024-10-04 09:05:35 UTC
I cannot access bug link provided. There is no useful information in this bug itself. Without access to any details known, this bug cannot be worked on.

Comment 2 Abhishek Raj 2024-10-04 09:11:56 UTC
(In reply to Petr Menšík from comment #1)
> I cannot access bug link provided. There is no useful information in this
> bug itself. Without access to any details known, this bug cannot be worked
> on.

A NULL pointer dereference was found in Unbound versions <= 1.20.0. The vulnerability occurs in the ub_ctx_set_fwd function in libunbound.c. When a specific sequence of API calls is made, the program attempts to read memory from a NULL pointer, resulting in a segmentation fault. This can cause the application to crash, leading to a denial of service. The issue is triggered by a particular use of the ub_ctx_set_fwd and ub_ctx_resolvconf functions. .

Comment 3 Abhishek Raj 2024-10-04 09:13:07 UTC
(In reply to Abhishek Raj from comment #2)
> (In reply to Petr Menšík from comment #1)
> > I cannot access bug link provided. There is no useful information in this
> > bug itself. Without access to any details known, this bug cannot be worked
> > on.
> 
> A NULL pointer dereference was found in Unbound versions <= 1.20.0. The
> vulnerability occurs in the ub_ctx_set_fwd function in libunbound.c. When a
> specific sequence of API calls is made, the program attempts to read memory
> from a NULL pointer, resulting in a segmentation fault. This can cause the
> application to crash, leading to a denial of service. The issue is triggered
> by a particular use of the ub_ctx_set_fwd and ub_ctx_resolvconf functions. .

Reference:
https://github.com/NLnetLabs/unbound/issues/1072
https://github.com/NLnetLabs/unbound/pull/1073/files

Comment 4 Petr Menšík 2024-10-04 10:08:05 UTC
Ah, excelent. This is too fixed with recent rebase to 1.21.0 (bug #2316313), in all releases to 1.21.1 (bug #2316313), but not yet added to updates.

Comment 5 Fedora Update System 2024-10-04 10:08:49 UTC
FEDORA-2024-a5d6cd9f0a (unbound-1.21.1-1.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-a5d6cd9f0a

Comment 6 Fedora Update System 2024-10-04 10:09:22 UTC
FEDORA-2024-c07e065747 (unbound-1.21.1-3.fc40) has been submitted as an update to Fedora 40.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-c07e065747

Comment 7 Fedora Update System 2024-10-04 10:09:51 UTC
FEDORA-2024-2ba00c906c (unbound-1.21.1-3.fc39) has been submitted as an update to Fedora 39.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-2ba00c906c

Comment 8 Fedora Update System 2024-10-06 02:11:44 UTC
FEDORA-2024-c07e065747 (unbound-1.21.1-3.fc40) has been pushed to the Fedora 40 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2024-10-10 00:16:56 UTC
FEDORA-2024-a5d6cd9f0a (unbound-1.21.1-1.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 10 Fedora Update System 2024-10-19 01:18:59 UTC
FEDORA-2024-2ba00c906c (unbound-1.21.1-3.fc39) has been pushed to the Fedora 39 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.