Echo: unbound: security update to 1.25.1-1

high Tenable Cloud Security Plugin ID 464003

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records
for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be
used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply
(i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor
can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by
address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or
fragmentation attacks. Unbound would then accept the relative address records in the additional section
and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the
delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the
additional section if they are not explicitly relevant only to authority NS records, mitigating the
possible poison effect. This is a complement fix to CVE-2025-11411. (CVE-2026-42960)

Solution

Update the unbound library and its related packages to version 1.25.1-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-42960

Plugin Details

Severity: High

ID: 464003

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.8

Percentile: 96.82

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-42960

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 5.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/21/2026

Vulnerability Publication Date: 5/20/2026

Reference Information

CVE: CVE-2026-42960