PT-2026-63380 · Nlnet · Unbound

·

CVE-2026-50046

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.15.0 through 1.25.1
Description A use-after-free issue exists in the handling of DNS-over-TLS (DoT) forwarded queries. The TLS server name is tied to the lifetime of the serviced query struct but is also referenced by the waiting tcp struct. If the serviced query struct is removed from the mesh while the DoT TCP stream is still handshaking, the storage for the referenced string is freed. A subsequent error in the TLS stream leads to a read-only dereference of the freed pointer, causing a daemon crash and resulting in a denial of service. This can be triggered by a malicious actor querying records in a specific zone while placing the system under pressure to trigger the jostle logic. This requires a stub or forward zone configured for DoT with a #authname suffix on the server identification, and a transient connectivity failure to the server.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1.

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92970
CVE-2026-50046
ECHO-C79D-4D79-8029
OESA-2026-3434
OESA-2026-3435
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound