CVE-2024-1488: Incorrect Default Permissions
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
AI Analysis
Technical Summary
The vulnerability in Unbound (CVE-2024-1488) stems from incorrect default permissions that permit any process outside the unbound group to modify the runtime configuration if it can connect to localhost on port 8953. The default configuration with "control-use-cert: no" and IP-based "control-interface" allows improper access. An attacker with local access can manipulate the running Unbound instance, potentially changing forwarders to monitor DNS queries or disrupt DNS resolution. Red Hat advisories for RHEL 8 and 9 provide updated Unbound packages that mitigate this by introducing a new configuration file (/etc/unbound/conf.d/remote-control.conf) which sets "control-interface" to a Unix socket and enables "control-use-cert: yes" to restrict access. Verification can be done using "unbound-control status | grep control" to check if SSL or named pipe control is enabled, indicating a non-vulnerable configuration. The advisories recommend updating to the fixed packages and adjusting configuration files accordingly.
Potential Impact
An unprivileged local attacker can connect to the Unbound control interface on localhost port 8953 and modify the runtime configuration. This can lead to manipulation of DNS forwarders, enabling tracking of all queries forwarded by the local resolver, and potentially disrupting DNS resolution. The vulnerability allows unauthorized configuration changes, which can compromise confidentiality and integrity of DNS operations and availability of DNS resolution.
Mitigation Recommendations
Red Hat has released updated Unbound packages for RHEL 8 and 9 that address this vulnerability. The fix involves adding a new configuration file (/etc/unbound/conf.d/remote-control.conf) that restricts control access to a Unix socket and enables certificate-based authentication (control-use-cert: yes). Users should update to the patched versions provided by Red Hat advisories RHSA-2024:1750 and RHSA-2024:1751. To verify if a system is vulnerable, run "unbound-control status | grep control"; output containing "control(ssl)" or "control(namedpipe)" indicates a non-vulnerable configuration. If only "control" is returned, the system is vulnerable and should be fixed by including the new configuration file or adding the directives to custom control configuration files. Follow Red Hat's update instructions at https://access.redhat.com/articles/11258.
CVE-2024-1488: Incorrect Default Permissions
Description
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
CVSS v3.1
Score 8.0high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Unbound (CVE-2024-1488) stems from incorrect default permissions that permit any process outside the unbound group to modify the runtime configuration if it can connect to localhost on port 8953. The default configuration with "control-use-cert: no" and IP-based "control-interface" allows improper access. An attacker with local access can manipulate the running Unbound instance, potentially changing forwarders to monitor DNS queries or disrupt DNS resolution. Red Hat advisories for RHEL 8 and 9 provide updated Unbound packages that mitigate this by introducing a new configuration file (/etc/unbound/conf.d/remote-control.conf) which sets "control-interface" to a Unix socket and enables "control-use-cert: yes" to restrict access. Verification can be done using "unbound-control status | grep control" to check if SSL or named pipe control is enabled, indicating a non-vulnerable configuration. The advisories recommend updating to the fixed packages and adjusting configuration files accordingly.
Potential Impact
An unprivileged local attacker can connect to the Unbound control interface on localhost port 8953 and modify the runtime configuration. This can lead to manipulation of DNS forwarders, enabling tracking of all queries forwarded by the local resolver, and potentially disrupting DNS resolution. The vulnerability allows unauthorized configuration changes, which can compromise confidentiality and integrity of DNS operations and availability of DNS resolution.
Mitigation Recommendations
Red Hat has released updated Unbound packages for RHEL 8 and 9 that address this vulnerability. The fix involves adding a new configuration file (/etc/unbound/conf.d/remote-control.conf) that restricts control access to a Unix socket and enables certificate-based authentication (control-use-cert: yes). Users should update to the patched versions provided by Red Hat advisories RHSA-2024:1750 and RHSA-2024:1751. To verify if a system is vulnerable, run "unbound-control status | grep control"; output containing "control(ssl)" or "control(namedpipe)" indicates a non-vulnerable configuration. If only "control" is returned, the system is vulnerable and should be fixed by including the new configuration file or adding the directives to custom control configuration files. Follow Red Hat's update instructions at https://access.redhat.com/articles/11258.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2024-02-14T12:47:25.283Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2024:1750","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1751","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1780","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1801","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1802","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:1804","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:2587","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:2696","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:0837","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-1488","vendor":"Red Hat"}]
Threat ID: 69135a44b36faa5b6c0e5fe3
Added to database: 11/11/2025, 15:46:12 UTC
Last enriched: 08/07/2026, 13:04:02 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 355
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.