CVE-2022-3204

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the attack and the replies, different limits could be reached. From version 1.16.3 on, Unbound introduces fixes for better performance when under load, by cutting opportunistic queries for nameserver discovery and DNSKEY prefetching and limiting the number of times a delegation point can issue a cache lookup for missing records.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
nlnetlabsunbound
𝑥
≤ 1.16.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
unbound
bookworm
1.17.1-2+deb12u2
fixed
bookworm (security)
1.17.1-2+deb12u2
fixed
bullseye
1.13.1-1+deb11u2
fixed
bullseye (security)
1.13.1-1+deb11u3
fixed
sid
1.22.0-1
fixed
trixie
1.22.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
unbound
bionic
Fixed 1.6.7-1ubuntu2.6
released
focal
Fixed 1.9.4-2ubuntu1.4
released
jammy
Fixed 1.13.1-1ubuntu5.3
released
kinetic
Fixed 1.16.2-1ubuntu0.1
released
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libunbound8
suse enterprise desktop 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise desktop 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise desktop 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.3.1
fixed
unbound-anchor
suse enterprise desktop 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise desktop 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise desktop 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.3.1
fixed
unbound-devel
suse enterprise desktop 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise desktop 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise desktop 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise sap 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP2
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP3
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.13.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.3.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3-unbound
RHEL 8
0:1.16.2-5.el8
fixed
RHEL 8.6 AUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 E4S
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 EUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 TUS
0:1.7.3-17.el8_6.5
fixed
RHEL 9
0:1.16.2-3.el9
fixed
unbound
RHEL 8
0:1.16.2-5.el8
fixed
RHEL 8.6 AUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 E4S
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 EUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 TUS
0:1.7.3-17.el8_6.5
fixed
RHEL 9
0:1.16.2-3.el9
fixed
unbound-devel
RHEL 8
0:1.16.2-5.el8
fixed
RHEL 8.6 AUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 E4S
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 EUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 TUS
0:1.7.3-17.el8_6.5
fixed
RHEL 9
0:1.16.2-3.el9
fixed
unbound-libs
RHEL 8
0:1.16.2-5.el8
fixed
RHEL 8.6 AUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 E4S
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 EUS
0:1.7.3-17.el8_6.5
fixed
RHEL 8.6 TUS
0:1.7.3-17.el8_6.5
fixed
RHEL 9
0:1.16.2-3.el9
fixed