PT-2026-93374 · Nlnet+1 · Unbound+1

·

CVE-2026-82717

·

Published

2026-09-16

·

Updated

2026-10-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.26.1
Description A heap buffer overflow exists in the DNSSEC validator. The issue occurs during CNAME synthesis when an upstream response requires the enforcement of a maximum TTL value in the packet buffer. If a compression pointer points to the overwritten value and invalidates the domain name, an error path fails to correctly move the buffer position, leading to progressive heap memory corruption. Depending on the system and compilation options, this can result in a crash or remote code execution. An attacker controlling a malicious zone can trigger this flaw by querying a vulnerable resolver.
Recommendations Update to a version newer than 1.26.0.

Fix

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:70754
ALSA-2026:71419
ALSA-2026:71487
AZL-101700
CVE-2026-82717
ECHO-30A9-8F50-CFD9
OPENSUSE-SU-2026:11930-1
USN-8873-1

Affected Products

Rocky Linux
Unbound