PT-2026-63393 · Nlnet · Unbound

·

CVE-2026-56444

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.20.0 through 1.25.1
Description An issue exists when the software is configured with serve-expired: yes and serve-expired-client-timeout is greater than discard-timeout (where discard-timeout is greater than 0). In this specific configuration, the discard-timeout branch within the serve expired logic drops an aged client reply without correctly decrementing the counter for the number of reply addresses for the query. Because the counter is not decremented, it can reach its maximum limit, causing new clients for duplicate in-flight queries to be silently dropped, which leads to a degradation of the resolution service. A malicious actor can trigger this by querying the resolver for a client-controlled slow-on-demand authoritative zone to push the counter past the threshold.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1. Ensure that serve-expired-client-timeout is not configured to be greater than discard-timeout when serve-expired is enabled.

Fix

DoS

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92955
CVE-2026-56444
ECHO-C184-6FD7-AE80
OESA-2026-3434
OESA-2026-3435
OESA-2026-3436
OESA-2026-3437
OESA-2026-3438
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound