CyberRota Analysis
AI-GeneratedApplications utilizing libunbound versions up to 1.25.1, configured with a non-zero 'unwanted-reply-threshold', are vulnerable to abrupt termination when the threshold is exceeded due to the absence of the 'libworker_alloc_cleanup' function in the allowed function call list. This can lead to a fatal exit of libunbound, impacting the stability of the embedding application. Organizations using libunbound in their applications should prioritize addressing this vulnerability to prevent potential service disruptions.
Original NVD Description
With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.
Related CVEs
Other vulnerabilities affecting the same vendor(s)