High severity7.5NVD Advisory· Published May 19, 2020· Updated Jun 17, 2026
CVE-2020-12662
CVE-2020-12662
Description
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- Unbound/Unbounddescription
- osv-coords11 versionspkg:rpm/opensuse/libunbound-devel-mini&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/opensuse/unbound&distro=openSUSE%20Tumbleweedpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/opensuse/unbound&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/unbound&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/libunbound-devel-mini&distro=openSUSE%20Leap%2015.2
< 1.6.8-lp151.8.3.1+ 10 more
- (no CPE)range: < 1.6.8-lp151.8.3.1
- (no CPE)range: < 1.6.8-3.6.1
- (no CPE)range: < 1.13.2-1.2
- (no CPE)range: < 1.6.8-10.3.1
- (no CPE)range: < 1.6.8-10.3.1
- (no CPE)range: < 1.6.8-3.6.1
- (no CPE)range: < 1.6.8-3.6.1
- (no CPE)range: < 1.6.8-3.6.1
- (no CPE)range: < 1.6.8-lp152.9.3.1
- (no CPE)range: < 1.6.8-lp151.8.3.1
- (no CPE)range: < 1.6.8-lp152.9.3.1
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
13- www.openwall.com/lists/oss-security/2020/05/19/5nvdMailing ListPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-06/msg00067.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-06/msg00069.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/02/msg00017.htmlnvdMailing ListThird Party Advisory
- nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txtnvdVendor Advisory
- security.freebsd.org/advisories/FreeBSD-SA-20:19.unbound.ascnvdThird Party Advisory
- security.netapp.com/advisory/ntap-20200702-0006/nvdThird Party Advisory
- usn.ubuntu.com/4374-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4694nvdThird Party Advisory
- www.synology.com/security/advisory/Synology_SA_20_12nvdThird Party Advisory
- www.nxnsattack.comnvdTechnical Description
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F5NFROI2OMCZLYRTCNGHGO3TUD32LCIQ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJ42N2HBZ3DXMSEC56SWIIOFQGOS5M7I/nvd
News mentions
0No linked articles in our index yet.