PT-2026-63390 · Nlnet · Unbound

·

CVE-2026-55990

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.7.0 through 1.25.1
Description When the dnscrypt: clause contains more dnscrypt-provider-cert: files than matching dnscrypt-secret-key: files, the software fails to properly initialize all slots, leaving some filled with 0xdb bytes from the libsodium allocator. Because the system iterates based on the number of certificate files rather than actual initialized slots, it may access these garbage entries. An unauthenticated client can trigger a server crash by sending a UDP datagram of 68 bytes or more to the dnscrypt-port where the first 8 bytes are 0xdb, leading to a garbage dereference. This issue requires the software to be compiled with DNSCrypt support using the --enable-dnscrypt flag.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1. Ensure that the number of dnscrypt-provider-cert: files does not exceed the number of dnscrypt-secret-key: files in the dnscrypt: configuration clause.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92973
CVE-2026-55990
ECHO-B416-47AD-FA4D
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound