Infinite loop in Unbound - CVE-2024-1931
Published: March 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in EDE support when trimming EDE text on
positive replies. A remote attacker can consume all available system resources and cause denial of service conditions.
Successful exploitation of the vulnerability requires enabled support for EDE (not a default option).
Affected software
Fedora
Oracle Solaris
unbound
IBM Cloud Transformation Advisor
How to mitigate CVE-2024-1931
unbound - addressed in versions 1.19.1-4.fc40, 1.19.3-1.fc38, 1.19.3-1.fc39, 1.19.3-1.fc40, 1.19.3-1.fc41
IBM Cloud Transformation Advisor - update to 3.10.0
Oracle Solaris - update to 11.4 SRU 71