CVE-2026-42944

EUVD-2026-31085
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
nlnetlabsunbound
1.14.0 ≤
𝑥
< 1.25.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
unbound
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.25.1-1
fixed
sid
1.25.1-1
fixed
trixie
vulnerable
trixie (security)
1.22.0-2+deb13u3
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libunbound8
suse enterprise desktop 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.16.1
fixed
unbound-anchor
suse enterprise desktop 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.16.1
fixed
unbound-devel
suse enterprise desktop 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise sap 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise sap 15 SP7
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP4
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP5
1.20.0-150100.10.25.1
fixed
suse enterprise server 15 SP6
1.20.0-150600.23.16.1
fixed
suse enterprise server 15 SP7
1.20.0-150600.23.16.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3-unbound
RHEL 8
0:1.16.2-5.11.el8_10
fixed
RHEL 9
0:1.24.2-3.el9_8.1
fixed
unbound
RHEL 8
0:1.16.2-5.11.el8_10
fixed
RHEL 9
0:1.24.2-3.el9_8.1
fixed
unbound-devel
RHEL 8
0:1.16.2-5.11.el8_10
fixed
RHEL 9
0:1.24.2-3.el9_8.1
fixed
unbound-dracut
RHEL 9
0:1.24.2-3.el9_8.1
fixed
unbound-libs
RHEL 8
0:1.16.2-5.11.el8_10
fixed
RHEL 9
0:1.24.2-3.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-unbound
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
python3-unbound-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-anchor
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-anchor-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-debugsource
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-devel
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-libs
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-libs-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-utils
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
unbound-utils-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.12
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
unbound
Azure Linux 3.0
0:1.25.1-1.azl3
fixed