CyberRota Analysis
AI-GeneratedNLnetLabs Unbound versions up to and including 1.26.0 are vulnerable to a degradation of service due to an unbounded number of consecutive reads in the TCP/DoT reading procedure. This allows a malicious actor to monopolize a worker's event loop by streaming distinct uncached names, potentially leading to service disruption. Organizations using affected versions should prioritize patching to mitigate the risk of denial-of-service attacks.
Original NVD Description
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.
Related CVEs
Other vulnerabilities affecting the same vendor(s)