NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
CVSS Details
- CVSS 4.0 Base Score: 9.1 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade unbound-develUpgrade unboundUpgrade unbound-libsUpgrade unbound-dracutUpgrade python3-unbound | Jun 16, 2026 | Jun 8, 2026 |
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade unbound-debuginfoUpgrade python2-unboundUpgrade unbound-develUpgrade unbound-anchorUpgrade python3-unboundUpgrade unbound-libsUpgrade unbound-utilsUpgrade unbound | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-libsUpgrade unbound-develUpgrade python3-unbound-debuginfoUpgrade unbound-utils-debuginfoUpgrade unbound-debugsourceUpgrade unbound-anchorUpgrade unbound-debuginfoUpgrade unbound-anchor-debuginfoUpgrade unbound-utilsUpgrade python3-unboundUpgrade unboundUpgrade unbound-libs-debuginfo | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Sep 1, 2026 | Aug 31, 2026 |
| Freebsd | — | Upgrade unboundUpgrade FreeBSD | Jun 15, 2026 | Jun 10, 2026 |
| Redhat_linux | — | Upgrade unboundUpgrade unbound-libsUpgrade unbound-debuginfoUpgrade unbound-anchorUpgrade unbound-libs-debuginfoUpgrade unbound-develUpgrade unbound-debugsourceUpgrade unbound-dracutUpgrade unbound-utilsUpgrade unbound-utils-debuginfoUpgrade python3-unboundUpgrade unbound-anchor-debuginfoNo solution existsUpgrade python3-unbound-debuginfo | Jun 8, 2026 | May 20, 2026 |
| Rocky_linux | — | Upgrade unbound-develUpgrade python3-unboundUpgrade unbound-libsUpgrade unbound-dracutUpgrade unbound-utils-debuginfoUpgrade unbound-utilsUpgrade unboundUpgrade unbound-anchorUpgrade unbound-anchor-debuginfoUpgrade python3-unbound-debuginfoUpgrade unbound-debugsourceUpgrade unbound-libs-debuginfoUpgrade unbound-debuginfo | Jun 8, 2026 | Jun 6, 2026 |
| Ubuntu | — | Upgrade unboundUpgrade libunbound8 | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub