PT-2026-42125 · Unbound+1 · Unbound+1
Qifan Zhang
·
Published
2026-05-20
·
Updated
2026-05-26
·
CVE-2026-33278
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.19.1 through 1.25.0
Description
A flaw in the DNSSEC validator allows for denial of service and potential remote code execution. The issue occurs during the deep copying of a data structure when DS sub-queries suspend validation due to NSEC3 computational budget exhaustion. A struct-assignment bug causes the destination pointer to be overwritten by the source pointer. When the sub-query region is subsequently freed, the resumed validator dereferences this dangling pointer, which can lead to a system crash or arbitrary code execution. An attacker can trigger this by controlling a malicious signed zone and querying the affected system.
Recommendations
Update to version 1.25.1.
Fix
DoS
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ubuntu
Unbound