Executive brief
Unbound is a DNS resolver that many organizations use to translate domain names into IP addresses. A flaw in how it processes DNS responses from name servers can cause a memory corruption issue that allows an attacker running a malicious name server to crash the resolver or potentially execute code. An attacker would need to control or intercept DNS responses, making this a risk for organizations that query untrusted or compromised upstream DNS servers.
Technical details
This is a heap buffer overflow vulnerability in the RRSet canonicalisation routine of Unbound. The root cause is a missing length check for the first owner name when validating buffer boundaries during canonicalisation. An attacker can craft a 255-byte query name with a large TCP response to overflow the heap buffer. The attack requires either a compromised upstream name server or the ability to intercept and modify DNS responses in transit (before DNSSEC validation occurs). An attacker can trigger a denial of service or potentially achieve code execution. The fix is available in Unbound 1.26.1, which adds the missing owner name to the buffer length check.
Affected products
- NLnet Labs Unbound up to and including 1.26.0
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Unbound 1.26.1 released with fix