CVE-2024-33655

Name
CVE-2024-33655
Description
The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://alas.aws.amazon.com/ALAS-2024-1934.html
cve@mitre.org https://datatracker.ietf.org/doc/html/rfc1035
cve@mitre.org https://github.com/NLnetLabs/unbound/commit/c3206f4568f60c486be6d165b1f2b5b254fea3de
cve@mitre.org https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#version-120
cve@mitre.org https://gitlab.isc.org/isc-projects/bind9/-/issues/4398
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3TBXPRJ2Q235YUZKYDRWOSYNDFBJQWJ3/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QITY2QBX2OCBTZIXD2A5ES62STFIA4AL/
cve@mitre.org https://meterpreter.org/researchers-uncover-dnsbomb-a-new-pdos-attack-exploiting-legitimate-dns-features/
cve@mitre.org https://nlnetlabs.nl/downloads/unbound/CVE-2024-33655.txt
cve@mitre.org https://nlnetlabs.nl/projects/unbound/security-advisories/
cve@mitre.org https://sp2024.ieee-security.org/accepted-papers.html
cve@mitre.org https://www.isc.org/blogs/2024-dnsbomb/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00019.html
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QITY2QBX2OCBTZIXD2A5ES62STFIA4AL/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TBXPRJ2Q235YUZKYDRWOSYNDFBJQWJ3/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
unbound edge-main 1.20.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
unbound 3.22-main 1.20.0-r0 None fixed
unbound 3.21-main 1.20.0-r0 None fixed
unbound 3.20-main 1.20.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
unbound 3.19-main 1.20.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
unbound 3.18-main 1.20.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
unbound 3.17-main 1.20.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed