Alibaba Cloud Linux 3 : 0020: unbound (ALINUX3-SA-2025:0020)

high Nessus Plugin ID 235973

Synopsis

The remote Alibaba Cloud Linux host is missing one or more security updates.

Description

The remote Alibaba Cloud Linux 3 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALINUX3-SA-2025:0020 advisory.

Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities:

CVE-2024-1488:
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVE-2024-8508:
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. The vulnerability can be exploited by a malicious actor querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations it is willing to do per packet. Packets that need more compression will result in semi- compressed packets or truncated packets, even on TCP for huge messages, to avoid locking the CPU for long.
This change should not affect normal DNS traffic.

Tenable has extracted the preceding description block directly from the Alibaba Cloud Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://mirrors.aliyun.com/alinux/3/cve/alinux3-sa-20250020.xml

Plugin Details

Severity: High

ID: 235973

File Name: alinux3_sa_2025-0020.nasl

Version: 1.1

Type: local

Published: 5/14/2025

Updated: 5/14/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:C/A:C

CVSS Score Source: CVE-2024-1488

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound, cpe:/o:alibabacloud:alibaba_cloud_linux_3, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound-libs-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound-devel, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:python3-unbound-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound-libs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:python3-unbound, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:unbound-debugsource

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Alibaba/release, Host/Alibaba/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 2/7/2025

Vulnerability Publication Date: 2/15/2024

Reference Information

CVE: CVE-2024-1488, CVE-2024-8508