ArchLinux: 201910-6: unbound: denial of service
Summary
Due to an error in parsing NOTIFY queries, it is possible for Unbound from 1.7.1 up to and including 1.9.3 to continue processing malformed queries and may ultimately result in a pointer dereference in uninitialized memory. This results in a crash of the Unbound daemon.
Resolution
Upgrade to 1.9.4-1.
# pacman -Syu "unbound>=1.9.4-1"
The problem has been fixed upstream in version 1.9.4.
References
https://www.nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt https://github.com/NLnetLabs/unbound/commit/b60c4a472c856f0a98120b7259e991b3a6507eb5 https://security.archlinux.org/CVE-2019-16866
Workaround
None.