DNS Cache Poisoning Vulnerability in NLnet Labs Unbound Software
CVE-2026-50252
5.7MEDIUM
What is CVE-2026-50252?
In NLnet Labs Unbound versions from 1.4.22 to 1.25.1, the UDP source port is randomized to enhance the confidentiality of DNS transactions. However, if resolver load balancing decisions are based on the source port, this mechanism can unintentionally expose the system to risks. The use of the SO_REUSEPORT configuration allows a determined attacker to exploit the predictable assignment of UDP source ports, rendering the system vulnerable to DNS cache poisoning attacks. By correlating the source UDP port and worker threads, an attacker can predictably lower the entropy of source port assignments, enabling malicious activities that compromise DNS resolution security.
Affected Version(s)
Unbound 1.4.22 < 1.25.2
References
CVSS V4
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Inbal Schussheim (Hebrew University)
Amit Klein (Hebrew University)
