The vendor explicitly identifies these products as affected by this CVE.
- unbound as a component of Red Hat Enterprise Linux 6
- unbound-devel as a component of Red Hat Enterprise Linux 6
- unbound-libs as a component of Red Hat Enterprise Linux 6
- unbound-python as a component of Red Hat Enterprise Linux 6
- unbound.src as a component of Red Hat Enterprise Linux 6
- unbound as a component of Red Hat Enterprise Linux 7
- unbound-devel as a component of Red Hat Enterprise Linux 7
- unbound-libs as a component of Red Hat Enterprise Linux 7
- unbound-python as a component of Red Hat Enterprise Linux 7
- unbound.src as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in Unbound, a Domain Name System (DNS) resolver. A remote attacker could trigger a heap overflow by sending specially crafted DNS reply packets. This occurs when Unbound attempts to encode multiple Name Server Identifier (NSID) or Extension Mechanisms for DNS (EDNS) Cookie options, or EDNS Padding options, and these options are enabled. Successful exploitation of this vulnerability could lead to a denial of service (DoS), making the Unbound service unavailable.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
