CVE-2019-25034
NixOS vulnerability analysis and mitigation

Overview

CVE-2019-25034 affects Unbound versions before 1.9.5, involving an integer overflow vulnerability in the sldns_str2wire_dname_buf_origin function that could lead to an out-of-bounds write. The vulnerability was discovered during a security audit by X41 D-SEC and was publicly disclosed in December 2019. However, the vendor disputes this as a vulnerability, stating that although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited (NVD, OSTIF).

Technical details

The vulnerability stems from an integer overflow condition in the sldns_str2wire_dname_buf_origin function within sldns/str2wire.c. When dlen + origin_len exceeds sizeof(size_t), the calculation wraps around, resulting in the addition value being smaller than the operands. This could potentially bypass buffer overflow checks and lead to memmove() writing out of bounds. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NetApp).

Impact

While the vulnerability could theoretically lead to out-of-bounds write operations which could result in remote code execution, data modification, or denial of service, the vendor disputes the practical exploitability of this issue. According to the vendor's assessment, although the code contains the vulnerability, a running Unbound installation cannot be exploited either remotely or locally (NVD).

Exploitability

The vulnerability was discovered during a security audit rather than being found in the wild. The vendor disputes the practical exploitability of this issue, indicating that while the code may be technically vulnerable, there are no known methods to exploit it in a running Unbound installation (OSTIF).

Mitigation and workarounds

The issue has been fixed in Unbound version 1.9.5 with commit a3545867fcdec50307c776ce0af28d07046a52dd. Users are recommended to upgrade to this version or later to address the vulnerability (Debian).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management