Bug 2479806 (CVE-2026-42959)
| Summary: | CVE-2026-42959 unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Unbound's DNSSEC validator when constructing chase-reply messages for validation. The code uses the wrong counter to calculate write offsets for ADDITIONAL section resource record sets. When a DNAME chain is combined with authority filtering, an uninitialized array slot is created that the validator later dereferences, causing an immediate process crash. Any application or infrastructure relying on Unbound for DNS resolution could be forced to exit unexpectedly, resulting in a denial-of-service condition.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2480119, 2481464 | ||
| Bug Blocks: | |||
| Deadline: | 2026-05-20 | ||
|
Description
OSIDB Bzimport
2026-05-19 11:35:15 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:23231 https://access.redhat.com/errata/RHSA-2026:23231 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:24365 https://access.redhat.com/errata/RHSA-2026:24365 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:24369 https://access.redhat.com/errata/RHSA-2026:24369 |