In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade unbound | Jul 29, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade unboundUpgrade unbound-anchorUpgrade unbound-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade unbound-anchor-debuginfoUpgrade unbound-develUpgrade python3-unbound-debuginfoUpgrade unbound-libsUpgrade python3-unboundUpgrade unbound-utils-debuginfoUpgrade unbound-debugsource | Aug 10, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade unbound | Sep 21, 2026 | Jul 22, 2026 |
| Freebsd | — | Upgrade unbound | Jul 28, 2026 | Jul 25, 2026 |
| Redhat_linux | — | No solution exists | Jul 27, 2026 | Jul 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jul 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub