CVE-2025-11411General

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respective address records) from YXDOMAIN and non-referral nodata replies, further mitigating the possible poison effect.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-16); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-02-16: 3Mentions · 2026-03-10: 3Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-10: 3Technical Details · 2026-02-16: 1Technical Details · 2026-03-10: 302-1603-1003-11
Signal classification3 categories
General
342.9%
Patch
342.9%
Disclosure
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-163
Disclosure1General2
2026-03-103
Patch3
2026-03-111
General1
Full discourse7 posts
  • Yasuhiro Morishita@OrangeMorishita
    General

    【自分用メモ】2025年10月に公開されたキャッシュポイズニング脆弱性の論文が出た。まだ読んでいない。 CVE-2025-40778(BIND)、CVE-2025-11411(Unbound)、CVE-2025-59023(PowerDNS Recursor) Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking - NDSS Symposium https://www.ndss-symposium.org/ndss-paper/should-i-trust-you-rethinking-the-principle-of-zone-based-isolation-dns-bailiwick-checking/

    Post summary

    A personal note noting a recent cache‑poisoning paper and listing three DNS resolver CVEs, without providing technical details, PoC, exploit code, or patch information.

    15412113.3K
    4.4K followersView on X
  • Tech Refreshing@TechRefreshing
    Patch

    FreeBSD 14.4 dropped today 🚀 ✅ OpenZFS 2.2.9 ✅ DNS cache poisoning fix (CVE-2025-11411) ✅ EFI installer fix ✅ Clean upgrade via freebsd-update Still the most reliable Unix system for servers & firewalls. Full review 👇 https://techrefreshing.com/freebsd-14-4-review/ #FreeBSD #BSD #Unix #SysAdmin

    Post summary

    FreeBSD 14.4 release acknowledges a fix for CVE-2025-11411—DNS cache poisoning—alongside other updates; it does not provide exploits, PoC, or active exploitation reports.

    060213613
    332 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-3094 2 - CVE-2025-43300 3 - CVE-2026-2796 4 - CVE-2026-1602 5 - CVE-2025-11411 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top 5 trending CVEs without providing additional technical, exploit, or mitigation details.

    00020223
    1.7K followersView on X
  • transilienceai@transilienceai
    General

    "Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking" is a research paper published in October 2025 that analyzes cache poisoning vulnerabilities in major DNS resolvers, including CVE-2025-40778 (BIND), CVE-2025-11411 (Unbound), and CVE-2025-59023 (PowerDNS Recursor). 📅🔍 It critiques the traditional zone-based isolation (DNS bailiwick checking) principle, arguing it fails under certain conditions, enabling attackers to inject forged records into caches. #DNS #Security

    Post summary

    The passage reports on a research paper that analyzes cache poisoning CVEs in DNS resolvers, noting bailiwick checking weaknesses but providing no PoC, exploit details, or patch information.

    1000089
    313 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @OrangeMorishita CVE-2025-11411 (Unbound up to 1.24.1) enables poisoning of NS RRsets, risking domain hijacks. ⚠️ CVE-2025-59023 (PowerDNS Recursor) presents a specific cache poisoning vector, less detailed in results but tied to the paper's analysis. #Unbound #PowerDNS

    Post summary

    The tweet discusses two DNS cache poisoning CVEs, describing their impact on domain hijacking, but it does not provide PoC, exploit code, evidence of active exploitation, or patch information.

    1000044
    313 followersView on X
  • newsfeedindia@newsfeedindia01
    Patch

    FreeBSD 14.4 dropped today 🚀 ✅ OpenZFS 2.2.9 ✅ DNS cache poisoning fix (CVE-2025-11411) ✅ EFI installer fix ✅ Clean upgrade via freebsd-update Still the most reliable Unix system for servers & firewalls. Full review 👇 https://techrefreshing.com/freebsd-14-4-review/ #FreeBSD #BSD #Unix #SysAdmin

    Post summary

    The release announcement highlights that FreeBSD 14.4 incorporates a patch for the DNS cache poisoning flaw identified as CVE‑2025‑11411.

    00000119
    1.9K followersView on X
  • anup yadav@anupyadav123
    Patch

    FreeBSD 14.4 dropped today 🚀 ✅ OpenZFS 2.2.9 ✅ DNS cache poisoning fix (CVE-2025-11411) ✅ EFI installer fix ✅ Clean upgrade via freebsd-update Still the most reliable Unix system for servers & firewalls. Full review 👇 https://techrefreshing.com/freebsd-14-4-review/ #FreeBSD #BSD #Unix #SysAdmin

    Post summary

    FreeBSD 14.4 release includes a corrective patch for CVE‑2025‑11411, addressing a DNS cache poisoning issue along with several other stability updates.

    00000109
    50 followersView on X

Explore more