{"id":"USN-7666-1","summary":"unbound vulnerabilities","details":"Xiang Li discovered that Unbound incorrectly handled EDNS Client Subnet\n(ECS) in certain configurations. A remote attacker could possibly use this\nissue to perform a cache poisoning attack called Rebirthday Attack.","modified":"2026-04-27T18:11:53.865085Z","published":"2025-07-22T15:58:09Z","related":["UBUNTU-CVE-2025-5994"],"upstream":["CVE-2025-5994","UBUNTU-CVE-2025-5994"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7666-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-5994"}],"affected":[{"package":{"name":"unbound","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/unbound@1.13.1-1ubuntu5.11?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.1-1ubuntu5.11"}]}],"versions":["1.13.1-1ubuntu1","1.13.1-1ubuntu3","1.13.1-1ubuntu5","1.13.1-1ubuntu5.1","1.13.1-1ubuntu5.2","1.13.1-1ubuntu5.3","1.13.1-1ubuntu5.4","1.13.1-1ubuntu5.5","1.13.1-1ubuntu5.7","1.13.1-1ubuntu5.8","1.13.1-1ubuntu5.10"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.13.1-1ubuntu5.11","binary_name":"libunbound8"},{"binary_name":"python3-unbound","binary_version":"1.13.1-1ubuntu5.11"},{"binary_name":"unbound","binary_version":"1.13.1-1ubuntu5.11"},{"binary_name":"unbound-anchor","binary_version":"1.13.1-1ubuntu5.11"},{"binary_name":"unbound-host","binary_version":"1.13.1-1ubuntu5.11"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-5994","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7666-1.json"}},{"package":{"name":"unbound","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/unbound@1.19.2-1ubuntu3.5?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.2-1ubuntu3.5"}]}],"versions":["1.17.1-2","1.18.0-2ubuntu1","1.18.0-2ubuntu2","1.19.1-1ubuntu1","1.19.2-1ubuntu1","1.19.2-1ubuntu3","1.19.2-1ubuntu3.1","1.19.2-1ubuntu3.2","1.19.2-1ubuntu3.3","1.19.2-1ubuntu3.4"],"ecosystem_specific":{"binaries":[{"binary_version":"1.19.2-1ubuntu3.5","binary_name":"libunbound8"},{"binary_name":"python3-unbound","binary_version":"1.19.2-1ubuntu3.5"},{"binary_name":"unbound","binary_version":"1.19.2-1ubuntu3.5"},{"binary_name":"unbound-anchor","binary_version":"1.19.2-1ubuntu3.5"},{"binary_name":"unbound-host","binary_version":"1.19.2-1ubuntu3.5"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-5994","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7666-1.json"}}],"schema_version":"1.7.5"}