PT-2026-63389 · Nlnet+1 · Unbound+1

·

CVE-2026-55973

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.23.0 through 1.25.1
Description When the dns-error-reporting: yes setting is enabled, the software incorrectly processes the EDNS Report-Channel option (code 18) from upstream responses. Specifically, it uses the option's length as the length of the agent domain but fails to use the returned length during domain name checks. If the agent domain is followed by garbage data, these bytes are appended to the synthetic er. report query name. During the execution of the find closest of type() function, the software strips labels using the query name length instead of stopping at the embedded root. This causes the process to walk one byte past the root and pass the first garbage byte to the dname query hash() function as a label length, resulting in a stack buffer overflow of the labuf variable. An attacker controlling a delegated zone can trigger this by sending a specially crafted upstream response, which is sufficient to terminate the daemon.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1. As a temporary mitigation, set dns-error-reporting to no to disable the affected functionality.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55841
ALSA-2026:55892
AZL-92919
CVE-2026-55973
ECHO-60A1-36C5-6226
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1

Affected Products

Rocky Linux
Unbound