PT-2026-42134 · Nlnet+3 · Unbound+3

·

CVE-2026-44390

·

Published

2026-05-20

·

Updated

2026-06-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.25.1
Description An issue exists when handling replies with very large RRsets (Resource Record sets) that require name compression. Malicious upstream responses containing very large RRsets with records that do not share a suffix above the root can cause the system to spend excessive time applying name compression to downstream replies. This can lead to degraded performance and denial of service. An adversary can trigger this by querying for specially crafted contents of a malicious zone. The process involves an unbounded operation that can lock the CPU until the packet is complete because the compression counter is not incremented when a compression tree lookup fails.
Recommendations Update to version 1.25.1.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44390
ECHO-D188-50DF-D53F
OPENSUSE-SU-2026:10903-1
OPENSUSE-SU-2026:21083-1
SUSE-SU-2026:21874-1
SUSE-SU-2026:21913-1
SUSE-SU-2026:22160-1
SUSE-SU-2026:22213-1
SUSE-SU-2026:2281-1
SUSE-SU-2026:2369-1
USN-8282-1

Affected Products

Freebsd
Linuxmint
Ubuntu
Unbound