unbound-1.24.2-3.el9_8.1
エラータID: AXSA:2026-1303:08
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Heap overflow and crash with multiple nsid, cookie, padding EDNS options (CVE-2026-42944)
* unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages (CVE-2026-42959)
* unbound: Unbound DNSSEC Validator Use-After-Free via Deep Copy Pointer Overwrite Leading to DoS and Possible Remote Code Execution (CVE-2026-33278)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-33278
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
CVE-2026-42944
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
CVE-2026-42959
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.
Update packages.
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.
N/A
SRPMS
- unbound-1.24.2-3.el9_8.1.src.rpm
MD5: 4aa8cf1d46c3a5cd57ad1d7ca3a66b34
SHA-256: 82d5d3415fb554f624707a0edce3f1ede146c44667cff79cd51534723d1fd256
Size: 6.67 MB
Asianux Server 9 for x86_64
- python3-unbound-1.24.2-3.el9_8.1.x86_64.rpm
MD5: c61a76d12c3c46e9e344cd9aa5bbbea6
SHA-256: a9bb0c7f2e461fe3b9e84c5ff2773bcb200487512f71f79d64db14ced0a19c8a
Size: 109.04 kB - unbound-1.24.2-3.el9_8.1.x86_64.rpm
MD5: 4555a679b793a5bd3a1d09300149ff63
SHA-256: 8f8bc4cb7f5b2c97c013654bb861f7342ce1ee62554031e43b00003cbc6a2ed3
Size: 1.05 MB - unbound-devel-1.24.2-3.el9_8.1.i686.rpm
MD5: 7895b867cc797c5eb58fc5e021e688a3
SHA-256: c061e3fb95ef0db8e998064289e8130540d88b417d2083d6a6452d31ae864667
Size: 39.28 kB - unbound-devel-1.24.2-3.el9_8.1.x86_64.rpm
MD5: f65f6a8e4df5368ee9fb6037b4e6a060
SHA-256: ea0c6f809eecad5fa5dbf33cb7768beb97426920689adf6dc5dac82bc3672a2d
Size: 39.26 kB - unbound-dracut-1.24.2-3.el9_8.1.x86_64.rpm
MD5: 8a3ebdb27e94ef4c0d0c1ed204e1c92f
SHA-256: a7f84cfd2f9934798dbec1a7f11ce3ebd9c4c6c6272a381a7343a3e9414c4893
Size: 10.12 kB - unbound-libs-1.24.2-3.el9_8.1.i686.rpm
MD5: e86fff72d51dcaf2b1c509851e2e1d97
SHA-256: 0a7dc7fcd52fbe56cd81927fc340730038cf7f02bccf023a28ee6154be0296b2
Size: 608.72 kB - unbound-libs-1.24.2-3.el9_8.1.x86_64.rpm
MD5: 7c157c049561b09988d5fc58525b3778
SHA-256: c50d4986dbfbb9112e7d22d2ec7e179b4962b9f9c45f4775959658f494f5695c
Size: 583.59 kB