#VU87205 Infinite loop in Unbound - CVE-2024-1931
Published: March 7, 2024
Unbound
NLnet Labs
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in EDE support when trimming EDE text on
positive replies. A remote attacker can consume all available system resources and cause denial of service conditions.
Successful exploitation of the vulnerability requires enabled support for EDE (not a default option).