Fedora Account System
Red Hat Associate
Red Hat Customer
Uncontrolled Resource Consumption vulnerability in the DNSSEC validator of the Unbound DNS resolver. The flaw is caused by the negative cache DS record code path not taking into account the limit on NSEC3 hash calculations introduced in Unbound 1.19.1. An adversary that controls a DNSSEC-signed zone can exploit this by signing NSEC3 records with acceptably high iterations for child delegations and querying a vulnerable Unbound. Unbound will keep performing the allowed hash calculations on the NSEC3 records without applying the mitigation limit. As a side effect, a global lock for the negative cache is held for the duration of the hashing, blocking other threads that need to consult the negative cache. Coordinated attacks could escalate the impact to a full denial-of-service.