CVE-2026-56416

EUVD-2026-47684
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.33%
Affected Products (NVD)
VendorProductVersion
nlnetlabsunbound
𝑥
< 1.25.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
unbound
bookworm
vulnerable
bookworm (security)
vulnerable
forky
1.26.0-2
fixed
sid
1.26.0-2
fixed
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
unbound
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libunbound8
suse enterprise desktop 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP7
1.25.2-150600.23.19.1
fixed
unbound-anchor
suse enterprise desktop 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP7
1.25.2-150600.23.19.1
fixed
unbound-devel
suse enterprise desktop 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise sap 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise sap 15 SP7
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP4
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP5
1.25.2-150100.10.28.1
fixed
suse enterprise server 15 SP6
1.25.2-150600.23.19.1
fixed
suse enterprise server 15 SP7
1.25.2-150600.23.19.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-unbound
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
python3-unbound-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-anchor
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-anchor-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-debugsource
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-devel
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-libs
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-libs-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-utils
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
unbound-utils-debuginfo
Amazon Linux 2023
0:1.17.1-1.amzn2023.0.13
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
unbound
Azure Linux 3.0
0:1.25.2-1.azl3
fixed