Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. Reference: https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/
please close, this is also an old issue.
Hi Paul, please note these are bugs created to keep track of flaws in Fedora/RHEL projects/products, not related to Fedora only. We usually create additional bugs for Fedora maintainers to let them know about issues in their components, but in these cases they were not created, so there is nothing else for you to do, because as you said these issues are already fixed in supported Fedora versions (I see Fedora 32 has 1.10.1, so that's alright).
Upstream patch: https://github.com/NLnetLabs/unbound/commit/226298bbd36f1f0fd9608e98c2ae85988b7bbdb8
Statement: There is no available reproducer or proof of concept for this issue, nor it was ever proven the buffer overflow can happen in practice. Indeed in the original report this issue was considered one that might not be triggered and for this reason its Impact is Moderate.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1853 https://access.redhat.com/errata/RHSA-2021:1853
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-25032
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2022:0632 https://access.redhat.com/errata/RHSA-2022:0632