Logo
vulnerabilityCVE-2022-30699
Name
CVE-2022-30699
Source
NVD ( link)Debian ( link)
Description
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
unbound
Patched

Vulnerability Rating#


6.5
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.25.1
Not Affected
buildroot
master
1.25.1
Not Affected
openwrt
master
1.25.1-r1
Not Affected
openwrt
openwrt-25.12
1.25.1-r1
Not Affected
yocto
master
1.25.1
Not Affected
yocto
scarthgap
1.19.3
Not Affected

Resolved with patches#


unbound (yocto:kirkstone)

#
Title
Author
Resolve
1
- Fix the novel ghost domain issues CVE-2022-30698 and
"W.C.A. Wijngaards" <wouter@nlnetlabs.nl>
CVE-2022-30698
CVE-2022-30699