With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unbound | Jul 29, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade unbound-utils-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade unboundUpgrade unbound-libsUpgrade unbound-develUpgrade unbound-anchorUpgrade python3-unboundUpgrade unbound-anchor-debuginfoUpgrade python3-unbound-debuginfoUpgrade unbound-debuginfoUpgrade unbound-debugsource | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade unbound | Sep 21, 2026 | Jul 22, 2026 |
| Freebsd | — | Upgrade unbound | Jul 28, 2026 | Jul 25, 2026 |
| Redhat_linux | — | No solution exists | Aug 21, 2026 | Jul 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub