Alpine: multiple unbound packages, py-unbound: security update to 1.19.2-r0

high Tenable Cloud Security Plugin ID 424584

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can
cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0
introduced a feature that removes EDE records from responses with size higher than the client's advertised
buffer size. Before removing all the EDE records however, it would try to see if trimming the extra text
fields on those records would result in an acceptable size while still retaining the EDE codes. Due to an
unchecked condition, the code that trims the text of the EDE records could loop indefinitely. This happens
when Unbound would reply with attached EDE information on a positive reply and the client's buffer size is
smaller than the needed space to include EDE records. The vulnerability can only be triggered when the
'ede: yes' option is used; non default configuration. From version 1.19.2 on, the code is fixed to avoid
looping indefinitely. (CVE-2024-1931)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-1931

Plugin Details

Severity: High

ID: 424584

Version: Revision 1.10

Type: Local

Published: 4/4/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2024-1931

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/7/2024

Reference Information

CVE: CVE-2024-1931