Fedora Account System
Red Hat Associate
Red Hat Customer
Acceptance of Extraneous Untrusted Data vulnerability in the DNS response scrubbing logic of the Unbound DNS resolver. The flaw allows promiscuous RRSets that complement DNS replies in the authority section to be cached when accompanied by address records in the additional section. Specifically, Unbound marks additional section address records as allowed for any authority RRSet type, not just NS records. A malicious actor can exploit this by injecting RRSets other than NS (e.g., MX) accompanied by address records via spoofed reply packets or fragmentation attacks. Unbound then accepts and caches the relative address records from the additional section if the authority RRSet has sufficient trust, enabling DNS cache poisoning.