unbound-1.16.2-5.el8

エラータID: AXSA:2023-5872:03

Release date: 
Tuesday, June 6, 2023 - 13:00
Subject: 
unbound-1.16.2-5.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack) (CVE-2022-3204)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-3204
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the attack and the replies, different limits could be reached. From version 1.16.3 on, Unbound introduces fixes for better performance when under load, by cutting opportunistic queries for nameserver discovery and DNSKEY prefetching and limiting the number of times a delegation point can issue a cache lookup for missing records.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. unbound-1.16.2-5.el8.src.rpm
    MD5: d123a653c830469396c0c58d89603ef0
    SHA-256: a51df3e3b7a76b65492780147cf6a08ea5ca86b0452e3fd8b66bbc00c342958f
    Size: 5.99 MB

Asianux Server 8 for x86_64
  1. python3-unbound-1.16.2-5.el8.x86_64.rpm
    MD5: 31b28649613077b6ffad89a9ba2bf56d
    SHA-256: 792f26acee7c75f9849fda50e7020dfa9ca9bd15a34715a10283bc3c41752012
    Size: 128.41 kB
  2. unbound-1.16.2-5.el8.x86_64.rpm
    MD5: 302b4f1e941f4053c4a77df1e42c25c0
    SHA-256: 638699002b280e6ed40ecead1094cf3290e244b9d578268cdc399e3adbb02ada
    Size: 0.99 MB
  3. unbound-devel-1.16.2-5.el8.i686.rpm
    MD5: 7e906299445e20ded921eb791cd15c49
    SHA-256: c025cb593c1b84d9a6078b314c9a7db95ef2b193daeea600732c1b554eff88ae
    Size: 55.82 kB
  4. unbound-devel-1.16.2-5.el8.x86_64.rpm
    MD5: 13cfec094fc03fbfc0f1aeefed501a19
    SHA-256: 986d74f05fe34104b00c3285124b4c9ff629dbdeb52fa164062f5d4c5327c7ec
    Size: 55.80 kB
  5. unbound-libs-1.16.2-5.el8.i686.rpm
    MD5: 0fd7a795eacd3e9f50b1ac51dab2a1f3
    SHA-256: c4df419374a0405b56a9435193723f42d9056e070d7dc1c7e3e2dcdb97ab51bd
    Size: 613.08 kB
  6. unbound-libs-1.16.2-5.el8.x86_64.rpm
    MD5: cfa1a8b084a1302dba1d9d33ecc2d91b
    SHA-256: 3d66adc1447e2dcfea0d379a7d24fa5ee24e523d1358dc744fb645c34cbda094
    Size: 572.75 kB