CVE-2020-28935
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-28935 affects NLnet Labs Unbound (up to version 1.12.0) and NLnet Labs NSD (up to version 4.3.3). The vulnerability was discovered in how these applications handle PID files, potentially allowing for a local symlink attack. The issue was reported by Mason Loring Bliss and was publicly disclosed in December 2020 (NLnet Labs Advisory).

Technical details

The vulnerability occurs when Unbound and NSD write their PID files. When opening an existing PID file for writing, the applications would follow symlinks if the file was a symbolic link instead of a regular file. After writing, an additional chown operation would make the Unbound/NSD user the owner of the file. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

If exploited, this vulnerability could lead to a Denial of Service condition on the system running Unbound/NSD. The impact requires an attacker to have local access to the limited permission user that Unbound/NSD runs as, and the ability to create a symlink pointing to a critical system file (NLnet Labs Advisory).

Exploitability

The vulnerability requires local access to the system and specific user permissions. An attacker would need access to the user account that Unbound/NSD runs as. The attack scenario involves creating a symlink in place of the PID file pointing to a critical file, then waiting for the service to be restarted with root privileges (NLnet Labs Advisory).

Mitigation and workarounds

The vulnerability was fixed in Unbound version 1.13.0 and NSD version 4.3.4. For earlier versions, patches are available that can be applied manually. For Unbound, the patch can be applied to versions 1.6.6 up to 1.12.0, while for NSD, the patch supports versions 4.2.3 up to 4.3.3. The fix can be applied using the patch command followed by running 'make install' (NLnet Labs Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management