NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
CVSS Details
- CVSS 4.0 Base Score: 8.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade unbound-develUpgrade unbound-dracutUpgrade python3-unboundUpgrade unboundUpgrade unbound-libs | Jun 8, 2026 | Jun 8, 2026 |
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade unbound-anchorUpgrade unbound-debuginfoUpgrade unboundUpgrade python3-unboundUpgrade unbound-develUpgrade unbound-libsUpgrade python2-unboundUpgrade unbound-utils | Jul 21, 2026 | Jul 21, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-develUpgrade unbound-utils-debuginfoUpgrade python3-unbound-debuginfoUpgrade unbound-libsUpgrade unbound-debugsourceUpgrade unboundUpgrade unbound-anchor-debuginfoUpgrade python3-unboundUpgrade unbound-debuginfoUpgrade unbound-utilsUpgrade unbound-anchorUpgrade unbound-libs-debuginfo | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jul 28, 2026 | Jul 27, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade unbound | Jun 15, 2026 | Jun 10, 2026 |
| Oracle_linux | — | Upgrade unboundUpgrade python3-unboundUpgrade unbound-develUpgrade unbound-libs | Jun 12, 2026 | May 20, 2026 |
| Redhat_linux | — | Upgrade unboundNo solution existsUpgrade unbound-debugsourceUpgrade unbound-anchorUpgrade unbound-utils-debuginfoUpgrade unbound-develUpgrade python3-unbound-debuginfoUpgrade unbound-dracutUpgrade python3-unboundUpgrade unbound-anchor-debuginfoUpgrade unbound-utilsUpgrade unbound-libs-debuginfoUpgrade unbound-debuginfoUpgrade unbound-libs | Jun 8, 2026 | May 20, 2026 |
| Rocky_linux | — | Upgrade unbound-anchorUpgrade unbound-dracutUpgrade unboundUpgrade unbound-develUpgrade unbound-debuginfoUpgrade unbound-libsUpgrade unbound-debugsourceUpgrade unbound-utils-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade python3-unbound-debuginfoUpgrade python3-unboundUpgrade unbound-anchor-debuginfo | Jun 8, 2026 | Jun 6, 2026 |
| Ubuntu | — | Upgrade libunbound8Upgrade unbound | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub