目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-32665— DNS-over-QUIC拒绝服务漏洞因`quic-size`预算绕过

CVSS 7.5 · High

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
NLnet LabsUnbound1.22.0< 1.25.2affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-32665の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
ソース: CVE Program / CVE List V5
脆弱性説明
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two streams, each sending a declared 65535-byte length prefix and then holding the streams open, a client can already trivially make Unbound roughly allocate double that amount. This is a remote availability issue / memory-accounting bypass in the downstream DoQ implementation that leads to denial of service for new DoQ clients. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
CWE-1284
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
NLnet LabsUnbound 1.22.0 ~ 1.25.2 -

II. CVE-2026-32665の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-32665のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-32665 厂商安全公告 (1)

Same Patch Batch · NLnet Labs · 2026-07-22 · 24 CVEs total

CVE-2026-559737.5 HIGH'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-406917.5 HIGHPacket of death for DNSCrypt over TCP
CVE-2026-446907.5 HIGHCross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-502486.5 MEDIUMBOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-528635.9 MEDIUMMemory corruption could lead to crash and denial of service
CVE-2026-557175.9 MEDIUM'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
CVE-2026-559915.9 MEDIUMRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-500465.9 MEDIUMPossible heap use-after-free in an error path when a DoT forwarded query is jostled out
CVE-2026-559905.9 MEDIUMPacket of death for a DNSCrypt misconfigured Unbound
CVE-2026-564445.9 MEDIUMDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout
CVE-2026-446215.9 MEDIUMLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abr
CVE-2026-145865.9 MEDIUMAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
CVE-2026-502515.3 MEDIUMAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-500455.3 MEDIUM'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-564164.8 MEDIUMPossible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVE-2026-465823.7 LOWA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply
CVE-2026-446873.7 LOWOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legi
CVE-2026-416373.7 LOWDegradation of resolution service from improperly accounted client-terminated DNS-over-QUI
CVE-2026-544783.7 LOWDNS Cookie bypass when combined with proxy-protocol use
CVE-2026-429553.7 LOWExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-tim

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-32665へのコメント

まだコメントはありません


コメントを残す