NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.
CVSS Details
- CVSS 4.0 Base Score: 8.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-unboundUpgrade unbound-dracutUpgrade unboundUpgrade unbound-develUpgrade unbound-libs | Jun 8, 2026 | Jun 8, 2026 |
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade unbound-utilsUpgrade unbound-libsUpgrade python3-unboundUpgrade python2-unboundUpgrade unbound-anchorUpgrade unboundUpgrade unbound-develUpgrade unbound-debuginfo | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-utils-debuginfoUpgrade python3-unboundUpgrade unbound-utilsUpgrade unbound-libsUpgrade unbound-develUpgrade unbound-anchorUpgrade unboundUpgrade unbound-debugsourceUpgrade unbound-debuginfoUpgrade unbound-anchor-debuginfoUpgrade unbound-libs-debuginfoUpgrade python3-unbound-debuginfo | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Sep 1, 2026 | Aug 31, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade unbound | Jun 15, 2026 | Jun 10, 2026 |
| Oracle_linux | — | Upgrade unbound-develUpgrade python3-unboundUpgrade unbound-libsUpgrade unbound | Jun 12, 2026 | May 20, 2026 |
| Redhat_linux | — | Upgrade unbound-debuginfoUpgrade unbound-anchor-debuginfoUpgrade python3-unbound-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-dracutUpgrade unbound-libsUpgrade unbound-debugsourceUpgrade unbound-utilsUpgrade unbound-develNo solution existsUpgrade unboundUpgrade python3-unboundUpgrade unbound-utils-debuginfoUpgrade unbound-anchor | Jun 8, 2026 | May 20, 2026 |
| Rocky_linux | — | Upgrade python3-unboundUpgrade python3-unbound-debuginfoUpgrade unbound-libsUpgrade unbound-utils-debuginfoUpgrade unbound-utilsUpgrade unbound-debugsourceUpgrade unbound-develUpgrade unboundUpgrade unbound-dracutUpgrade unbound-debuginfoUpgrade unbound-anchor-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-anchor | Jun 8, 2026 | Jun 6, 2026 |
| Ubuntu | — | Upgrade unboundUpgrade libunbound8 (Ubuntu Pro)Upgrade libunbound2 (Ubuntu Pro)Upgrade libunbound8Upgrade unbound (Ubuntu Pro) | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub