Executive brief
Unbound is a widely used DNS resolver that translates human-readable domain names into IP addresses. A vulnerability in how it handles specific technical requests can allow an attacker to crash the service by sending specially crafted network traffic. This could lead to a denial-of-service, preventing users and applications from accessing websites or other internet services.
Technical details
A heap overflow vulnerability exists in Unbound's EDNS option encoding logic. The flaw is caused by a combination of improper de-duplication of EDNS options (NSID, DNS Cookie, and Padding) and an integer truncation error during the size calculation of the EDNS field. An unauthenticated remote attacker can trigger this by sending a DNS query containing multiple instances of these options, provided the corresponding features (nsid, answer-cookie, or pad-responses) are enabled in the configuration. This results in a heap-based buffer overflow of Unbound-controlled data, typically leading to a daemon crash (Denial of Service). The issue is resolved in version 1.25.1 by implementing option de-duplication and correcting the size calculation logic.
Affected products
- NLnet Labs Unbound 1.14.0 through 1.25.0
Timeline
- 2026-05-20: advisory: Initial disclosure by NLnet Labs
- 2026-05-20: patched: Unbound 1.25.1 released with fixes