PT-2026-42134 · Nlnet+5 · Unbound+5

·

CVE-2026-44390

·

Published

2026-05-20

·

Updated

2026-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.25.1
Description An issue exists when handling replies with very large RRsets (Resource Record sets) that require name compression. Malicious upstream responses containing very large RRsets with records that do not share a suffix above the root can cause the system to spend excessive time applying name compression to downstream replies. This can lead to degraded performance and denial of service. An adversary can trigger this by querying for specially crafted contents of a malicious zone. The process involves an unbounded operation that can lock the CPU until the packet is complete because the compression counter is not incremented when a compression tree lookup fails.
Recommendations Update to version 1.25.1.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36320
ALSA-2026:36777
ALSA-2026:37282
AZL-87045
BDU:2026-10812
CVE-2026-44390
ECHO-D188-50DF-D53F
OESA-2026-2606
OESA-2026-2607
OESA-2026-2608
OESA-2026-2609
OPENSUSE-SU-2026:10903-1
OPENSUSE-SU-2026:21083-1
RHSA-2026:24013
SUSE-SU-2026:21874-1
SUSE-SU-2026:21913-1
SUSE-SU-2026:22160-1
SUSE-SU-2026:22213-1
SUSE-SU-2026:2281-1
SUSE-SU-2026:2369-1
USN-8282-1

Affected Products

Freebsd
Linuxmint
Red Os
Rocky Linux
Ubuntu
Unbound