PT-2026-63371 · Unbound · Unbound

·

CVE-2026-40691

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Unbound versions 1.9.0 through 1.25.1
Description A heap-based buffer overflow occurs when a DNSCrypt query is received over TCP. The routine responsible for encrypting the reply in place does not bound the reply length against the destination buffer size, failing to apply the size clamp used in the UDP path. Consequently, a reply exceeding 65504 bytes is shifted forward by 48 bytes within a buffer of capacity msg-buffer-size, resulting in a write operation past the end of the heap allocation. This can be triggered by a single malicious encrypted query, causing the resolver to crash and leading to a denial of service. This issue requires the software to be compiled with DNSCrypt support via --enable-dnscrypt and the dnscrypt: clause to be configured and enabled for listening interfaces.
Recommendations Update Unbound to a version later than 1.25.1. As a temporary mitigation, disable the dnscrypt: clause on listening interfaces or avoid compiling the software with the --enable-dnscrypt option.

Fix

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92949
CVE-2026-40691
ECHO-C9BD-BA81-0BAE
OESA-2026-3334
OESA-2026-3335
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound