← Vulnerability feed

Vulnerability record · CVE-2024-1488 · published 15 February 2024

CVE-2024-1488: Fedoraproject unbound incorrect default permissions vulnerability

Fedoraproject · Unbound

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

7.3 CVSS 3.1 High EPSS 0.32% · top 77.4% CWE-276 · Incorrect default permissions
7.3CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
19Affected product versions listed by NVD
21References
6 Aug 2026Last modified by NVD

Description

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1488 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-8720WebKit memory corruption allows code execution via crafted web contentWebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful e…KEVEPSS 1.6%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed8.8CVE-2023-5869Postgresql integer overflow vulnerabilityA flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array va…EPSS 4.3%8.8CVE-2022-0435Linux kernel TIPC stack overflow via oversized domain member node countA stack overflow exists in the Linux kernel TIPC protocol handling when a packet declares more than the 64 allowed domain member nodes. The out-of-bo…EPSS 68%analysed8.8CVE-2021-3656Linux kernel missing authorization vulnerabilityA flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…EPSS 0.66%8.8CVE-2021-44142Samba vfs_fruit heap out-of-bounds read/write enables code executionSamba's vfs_fruit module mishandles extended file attributes (xattr), allowing out-of-bounds heap reads and writes when specially crafted EAs are pro…EPSS 73%analysed

Source: NIST National Vulnerability Database (record CVE-2024-1488), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.