AZL-101724

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101724.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-101724
Upstream
  • CVE-2026-80225
Published
2026-09-16T09:17:06Z
Modified
2026-09-18T05:37:08Z
Summary
CVE-2026-80225 affecting package unbound 1.26.0-1
Details

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.

References

Affected packages

Azure Linux:3 / unbound

Package

Name
unbound
Purl
pkg:rpm/azure-linux/unbound

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.26.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101724.json"