CVE-2024-43168

NameCVE-2024-43168
DescriptionA heap-buffer-overflow flaw was found in the cfg_mark_ports function within Unbound's config_file.c, which can lead to memory corruption. This issue could allow an attacker with local access to provide specially crafted input, potentially causing the application to crash or allowing arbitrary code execution. This could result in a denial of service or unauthorized actions on the system.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
unbound (PTS)jessie, jessie (lts)1.4.22-3+deb8u4vulnerable
stretch1.6.0-3+deb9u2vulnerable
buster (security), buster, buster (lts)1.9.0-2+deb10u4vulnerable
bullseye (security), bullseye1.13.1-1+deb11u2vulnerable
bookworm (security), bookworm1.17.1-2+deb12u2vulnerable
sid, trixie1.20.0-1fixed
unbound1.9 (PTS)stretch (security)1.9.0-2+deb10u2~deb9u2vulnerable
stretch (lts), stretch1.9.0-2+deb10u2~deb9u4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
unboundsourcejessie(unfixed)end-of-life
unboundsourcestretch(unfixed)end-of-life
unboundsource(unstable)1.20.0-1
unbound1.9source(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2303462
https://github.com/NLnetLabs/unbound/issues/1039
https://github.com/NLnetLabs/unbound/pull/1040
Fixed by: https://github.com/NLnetLabs/unbound/commit/193401e7543a1e561dd634a3eaae932fa462a2b9 (release-1.20.0rc1)

Search for package or bug name: Reporting problems