Integer Overflow Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2019-25033
9.8CRITICAL
What is CVE-2019-25033?
An integer overflow vulnerability exists in the Unbound DNS Resolver before version 1.9.5 due to the misuse of the ALIGN_UP macro in the regional allocator. While the vendor has expressed skepticism regarding the seriousness of this issue, they acknowledge that the flawed code could potentially allow for unforeseen behavior. However, it is important to note that a running instance of Unbound is not believed to be exploitable, neither remotely nor locally, thus limiting the actual risk posed by this flaw.
