Description
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
This issue is fixed starting with version 1.26.1
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound. | |
| Title | Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-09-16T08:30:58.604Z
Reserved: 2026-09-07T14:06:21.956Z
Link: CVE-2026-81642
No data.
Status : Received
Published: 2026-09-16T09:17:06.320
Modified: 2026-09-16T09:17:06.320
Link: CVE-2026-81642
No data.
OpenCVE Enrichment
No data.
Weaknesses