Executive brief
Unbound is a widely used DNS resolver that translates human-readable domain names into IP addresses. A vulnerability in its DNSCrypt feature allows a remote attacker to crash the service by sending a single specially crafted network request. This results in a denial of service, preventing users and systems from resolving domain names and potentially disrupting internet connectivity for the affected network.
Technical details
A heap-based buffer overflow exists in Unbound's DNSCrypt implementation when processing queries over TCP. The vulnerability occurs because the routine responsible for encrypting replies in place fails to validate the reply length against the destination buffer size on the TCP path, a check that is correctly implemented for UDP. Specifically, a reply exceeding 65,504 bytes is shifted forward by 48 bytes within a buffer sized by 'msg-buffer-size', leading to an out-of-bounds write. This requires Unbound to be compiled with '--enable-dnscrypt' and have the 'dnscrypt:' configuration enabled. An attacker can exploit this to crash the resolver process. The issue is resolved in version 1.25.2.
Affected products
- NLnet Labs Unbound 1.9.0 up to and including 1.25.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched: Fixed in Unbound 1.25.2