Executive brief
Unbound is a widely-used DNS resolver software that processes DNS queries and responses. A heap buffer overflow vulnerability in versions up to 1.26.0 can corrupt memory when handling certain DNS responses with CNAME records and compression pointers, potentially causing service crashes or remote code execution on affected systems. This affects DNS infrastructure and any services relying on Unbound for domain name resolution.
Technical details
The vulnerability is a heap buffer overflow in Unbound's DNS packet handling, specifically triggered during CNAME synthesis when enforcing a max TTL value rewrite in the packet buffer. When a compression pointer references an overwritten value that invalidates a domain name, the error path fails to advance the buffer position correctly, allowing heap memory to be overwritten. The attack requires an upstream DNS response with specific packet structure; no authentication is needed. An attacker with the ability to send crafted DNS responses can corrupt heap memory, typically resulting in a crash, and under specific system configurations and compilation options may achieve remote code execution. Unbound 1.26.1 and patched versions of 1.26.0 address the vulnerability.
Affected products
- NLnet Labs Unbound up to and including 1.26.0
Timeline
- 2026-09-16: disclosed: CVE-2026-82717 published
- 2026-09-16: patched: Unbound 1.26.1 released with fix