Fedora Account System
Red Hat Associate
Red Hat Customer
A denial of service vulnerability has been discovered in Unbound when compiled with DNSCrypt support ('--enable-dnscrypt'). A single bad DNSCrypt query over TCP could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow and eventual server crash and denial of service. Unbound 1.25.2 includes fixes to select the proper buffer TCP buffer for DNSCrypt, to properly check against the buffer's capacity and to clear the buffer before writing the dnscrypt contents otherwise UDP queries can hit assertions.