CVE-2020-12662: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.10 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Nlnetlabs Unbound: before 1.10.1 (fixed in 1.10.1)
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-05-19. Last modified 2026-06-17.