Nlnet · Unbound · CVE-2026-82717
**Name of the Vulnerable Software and Affected Versions**
NLnet Labs Unbound versions prior to 1.26.1
**Description**
A heap buffer overflow exists in the DNSSEC validator. The issue occurs during CNAME synthesis when an upstream response requires the enforcement of a maximum TTL value in the packet buffer. If a compression pointer points to the overwritten value and invalidates the domain name, an error path fails to correctly move the buffer position, leading to progressive heap memory corruption. Depending on the system and compilation options, this can result in a crash or remote code execution. An attacker controlling a malicious zone can trigger this flaw by querying a vulnerable resolver.
**Recommendations**
Update to a version newer than 1.26.0.