Skip to main content
EPSS 0.3%top 75%

Red Hat Security Advisory: unbound security update

0
High
Published: 01/30/2025 (01/30/2025, 13:00:00 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Two security vulnerabilities have been identified in the unbound DNS resolver packages used in Red Hat Enterprise Linux 8 and 9. CVE-2024-1488 allows unrestricted reconfiguration by any local process, potentially leading to local privilege escalation. CVE-2024-8508 involves unbounded name compression that could cause a denial of service. Red Hat has issued security updates to address these issues and recommends applying the provided patches. The update includes configuration changes to restrict access to unbound's control interface, mitigating the risk of unauthorized configuration changes. These vulnerabilities have been rated with high importance by Red Hat Product Security.

Affected software

Affected versions
=1.16.2-5.8.el8_10=1.16.2>=8 <9>=9 <10

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 16:17:13 UTC

Technical Analysis

The unbound DNS resolver in Red Hat Enterprise Linux versions 8 and 9 contains two vulnerabilities. CVE-2024-1488 arises from incorrect default permissions allowing any local process to modify the unbound runtime configuration via the control interface on localhost port 8953, enabling potential local privilege escalation. The vulnerability is mitigated by adding a new configuration file (/etc/unbound/conf.d/remote-control.conf) that restricts control interface access to members of the unbound group and enforces certificate usage. CVE-2024-8508 involves unbounded name compression that could lead to denial of service conditions. Red Hat has released updated packages (e.g., unbound-1.16.2-5.8.el8_10) for affected architectures and versions, including x86_64, aarch64, ppc64le, and s390x, to fix these issues. The vendor advisory provides detailed instructions for verifying and applying the fix.

Potential Impact

CVE-2024-1488 allows an unprivileged local process to alter the running unbound DNS resolver configuration, potentially leading to local privilege escalation and manipulation of DNS forwarding behavior. CVE-2024-8508 could cause denial of service through unbounded name compression. These vulnerabilities impact the integrity and availability of the DNS resolver service on affected Red Hat Enterprise Linux systems.

Mitigation Recommendations

Red Hat has released official security updates that address these vulnerabilities. Users should apply the updated unbound packages provided in the advisory (e.g., unbound-1.16.2-5.8.el8_10 for RHEL 8 and corresponding updates for RHEL 9). Additionally, verify that the unbound configuration includes the new remote-control.conf file with directives to restrict control interface access and enable certificate usage. Use the command 'unbound-control status | grep control' to confirm that the configuration is not vulnerable. Systems updated with these packages and configuration changes are considered protected. No further action is required beyond applying the official patches and configuration updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:1750
Cve Count
1

Threat ID: 6a3da1fc4853345fc1835ccd

Added to database: 06/25/2026, 21:47:40 UTC

Last enriched: 08/21/2026, 16:17:13 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 92

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses