{"id":"CVE-2024-1488","title":"A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration","summary":"A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","cwe":["CWE-276","CWE-276"],"vendor":"fedoraproject","product":"unbound","affected":["unbound < 1.19.1-2.fc40","codeready_linux_builder = 9.0","codeready_linux_builder_eus = 9.2","codeready_linux_builder_eus = 9.4","codeready_linux_builder_eus_for_power_little_endian = 9.0_ppc64le","codeready_linux_builder_eus_for_power_little_endian = 9.2_ppc64le","codeready_linux_builder_for_arm64 = 9.0_aarch64","codeready_linux_builder_for_arm64 = 9.2_aarch64","codeready_linux_builder_for_arm64_eus = 9.4_aarch64","codeready_linux_builder_for_ibm_z_systems = 9.0_s390x","codeready_linux_builder_for_ibm_z_systems = 9.2_s390x","codeready_linux_builder_for_ibm_z_systems_eus = 9.4_s390x","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux_eus = 8.6","enterprise_linux_eus = 8.8","enterprise_linux_eus = 9.2","enterprise_linux_eus = 9.4","enterprise_linux_for_arm_64 = 8.0_aarch64","enterprise_linux_for_arm_64 = 9.0_aarch64","enterprise_linux_for_arm_64 = 9.2_aarch64","enterprise_linux_for_arm_64_eus = 8.6_aarch64","enterprise_linux_for_arm_64_eus = 8.8_aarch64","enterprise_linux_for_arm_64_eus = 9.4_aarch64","enterprise_linux_for_ibm_z_systems = 8.0_s390x","enterprise_linux_for_ibm_z_systems = 9.0_s390x","enterprise_linux_for_ibm_z_systems = 9.2_s390x","enterprise_linux_for_ibm_z_systems_eus = 8.6_s390x","enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x","enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x","enterprise_linux_for_power_little_endian = 8.0_ppc64le","enterprise_linux_for_power_little_endian = 9.0_ppc64le","enterprise_linux_for_power_little_endian = 9.2_ppc64le","enterprise_linux_for_power_little_endian_eus = 8.6_ppc64le","enterprise_linux_for_power_little_endian_eus = 8.8_ppc64le","enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le","enterprise_linux_server_aus = 8.2","enterprise_linux_server_aus = 8.4","enterprise_linux_server_aus = 8.6","enterprise_linux_server_aus = 9.2","enterprise_linux_server_aus = 9.4","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.2_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64le","enterprise_linux_server_tus = 8.2","enterprise_linux_server_tus = 8.4","enterprise_linux_server_tus = 8.6","enterprise_linux_server_tus = 8.8"],"patched":["unbound 1.19.1-2.fc40"],"published":"2024-02-15","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-1488","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:1750","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1751","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1780","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1801","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1802","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1804","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2587","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2696","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0837","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-1488","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2264183","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1750","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1751","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1780","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1801","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1802","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1804","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2587","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2696","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2024-1488","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2264183","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00321,"epssPercentile":0.253,"ingestedAt":"2026-08-06T23:06:29.027Z","slug":"CVE-2024-1488","body":"## Overview\n\nA vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.\n\n## Affected\n\n- `unbound < 1.19.1-2.fc40`\n- `codeready_linux_builder = 9.0`\n- `codeready_linux_builder_eus = 9.2`\n- `codeready_linux_builder_eus = 9.4`\n- `codeready_linux_builder_eus_for_power_little_endian = 9.0_ppc64le`\n- `codeready_linux_builder_eus_for_power_little_endian = 9.2_ppc64le`\n- `codeready_linux_builder_for_arm64 = 9.0_aarch64`\n- `codeready_linux_builder_for_arm64 = 9.2_aarch64`\n- `codeready_linux_builder_for_arm64_eus = 9.4_aarch64`\n- `codeready_linux_builder_for_ibm_z_systems = 9.0_s390x`\n- `codeready_linux_builder_for_ibm_z_systems = 9.2_s390x`\n- `codeready_linux_builder_for_ibm_z_systems_eus = 9.4_s390x`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux_eus = 8.6`\n- `enterprise_linux_eus = 8.8`\n- `enterprise_linux_eus = 9.2`\n- `enterprise_linux_eus = 9.4`\n- `enterprise_linux_for_arm_64 = 8.0_aarch64`\n- `enterprise_linux_for_arm_64 = 9.0_aarch64`\n- `enterprise_linux_for_arm_64 = 9.2_aarch64`\n- `enterprise_linux_for_arm_64_eus = 8.6_aarch64`\n- `enterprise_linux_for_arm_64_eus = 8.8_aarch64`\n- `enterprise_linux_for_arm_64_eus = 9.4_aarch64`\n- `enterprise_linux_for_ibm_z_systems = 8.0_s390x`\n- `enterprise_linux_for_ibm_z_systems = 9.0_s390x`\n- `enterprise_linux_for_ibm_z_systems = 9.2_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.6_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x`\n- `enterprise_linux_for_power_little_endian = 8.0_ppc64le`\n- `enterprise_linux_for_power_little_endian = 9.0_ppc64le`\n- `enterprise_linux_for_power_little_endian = 9.2_ppc64le`\n- `enterprise_linux_for_power_little_endian_eus = 8.6_ppc64le`\n- `enterprise_linux_for_power_little_endian_eus = 8.8_ppc64le`\n- `enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le`\n- `enterprise_linux_server_aus = 8.2`\n- `enterprise_linux_server_aus = 8.4`\n- `enterprise_linux_server_aus = 8.6`\n- `enterprise_linux_server_aus = 9.2`\n- `enterprise_linux_server_aus = 9.4`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.2_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64le`\n- `enterprise_linux_server_tus = 8.2`\n- `enterprise_linux_server_tus = 8.4`\n- `enterprise_linux_server_tus = 8.6`\n- `enterprise_linux_server_tus = 8.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unbound 1.19.1-2.fc40`","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}