Junglewise Threat Intelligence

CVE-2026-81634: NLnet Labs Unbound heap buffer overflow in RRSet canonicalisation

CVE-2026-81634 · Severity: high · CVSS 7.5 · Published 2026-09-16

Technologies: NLnet Labs Unbound. Vendors: NLnet Labs.

Executive brief

Unbound is a DNS resolver that many organizations use to translate domain names into IP addresses. A flaw in how it processes DNS responses from name servers can cause a memory corruption issue that allows an attacker running a malicious name server to crash the resolver or potentially execute code. An attacker would need to control or intercept DNS responses, making this a risk for organizations that query untrusted or compromised upstream DNS servers.

Technical details

This is a heap buffer overflow vulnerability in the RRSet canonicalisation routine of Unbound. The root cause is a missing length check for the first owner name when validating buffer boundaries during canonicalisation. An attacker can craft a 255-byte query name with a large TCP response to overflow the heap buffer. The attack requires either a compromised upstream name server or the ability to intercept and modify DNS responses in transit (before DNSSEC validation occurs). An attacker can trigger a denial of service or potentially achieve code execution. The fix is available in Unbound 1.26.1, which adds the missing owner name to the buffer length check.

Affected products

  • NLnet Labs Unbound up to and including 1.26.0

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Unbound 1.26.1 released with fix

References

Related threats