目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-40691— DNSCrypt over TCP 死亡数据包漏洞

CVSS 7.5 · High

Possible ATT&CK Techniques 1AI

T1498 · Network Denial of Service
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-40691の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Packet of death for DNSCrypt over TCP
ソース: NVD (National Vulnerability Database)
脆弱性説明
In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
堆缓冲区溢出
ソース: NVD (National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
NLnet LabsUnbound 1.9.0 ~ 1.25.2 -

II. CVE-2026-40691の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-40691のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-40691 其他参考 (1)

Same Patch Batch · NLnet Labs · 2026-07-22 · 24 CVEs total

CVE-2026-559737.5 HIGH'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-326657.5 HIGHRemote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-446907.5 HIGHCross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-502486.5 MEDIUMBOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-528635.9 MEDIUMMemory corruption could lead to crash and denial of service
CVE-2026-557175.9 MEDIUM'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
CVE-2026-559915.9 MEDIUMRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-500465.9 MEDIUMPossible heap use-after-free in an error path when a DoT forwarded query is jostled out
CVE-2026-559905.9 MEDIUMPacket of death for a DNSCrypt misconfigured Unbound
CVE-2026-564445.9 MEDIUMDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout
CVE-2026-446215.9 MEDIUMLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abr
CVE-2026-145865.9 MEDIUMAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
CVE-2026-502515.3 MEDIUMAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-500455.3 MEDIUM'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-564164.8 MEDIUMPossible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVE-2026-465823.7 LOWA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply
CVE-2026-446873.7 LOWOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legi
CVE-2026-416373.7 LOWDegradation of resolution service from improperly accounted client-terminated DNS-over-QUI
CVE-2026-544783.7 LOWDNS Cookie bypass when combined with proxy-protocol use
CVE-2026-429553.7 LOWExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-tim

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-40691へのコメント

まだコメントはありません


コメントを残す