PT-2026-63375 · Nlnet · Unbound+1

·

CVE-2026-44621

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.25.2
Description Applications using libunbound configured with the unwanted-reply-threshold parameter may be abruptly terminated. This occurs when the threshold is reached and libunbound attempts to call the libworker alloc cleanup() function, which is missing from the function call allow list. The issue is triggered when the unwanted-reply-threshold is set to a non-zero value and the iterator queries an authoritative server that sends enough UDP datagrams with incorrect transaction IDs to exceed that threshold, resulting in a fatal exit of libunbound and the termination of the embedding application.
Recommendations Update to version 1.25.2 or later. As a temporary workaround, set the unwanted-reply-threshold parameter to zero.

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92943
CVE-2026-44621
ECHO-0093-F01D-663C
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound
Libunbound