Bug 2535059 (CVE-2026-81642)

Summary: CVE-2026-81642 unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Unbound's DNSSEC validator. A remote attacker can exploit this vulnerability by controlling a malicious zone and sending a specially crafted DNSKEY record. This can lead to a heap buffer overflow, potentially resulting in a denial of service or remote code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2536324    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-16 09:07:56 UTC
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.

Comment 2 Jon Orris 2026-09-23 13:22:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:70754 https://access.redhat.com/errata/RHSA-2026:70754

Comment 3 Jon Orris 2026-09-23 13:22:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:70754 https://access.redhat.com/errata/RHSA-2026:70754

Comment 4 Jon Orris 2026-09-24 08:46:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:71459 https://access.redhat.com/errata/RHSA-2026:71459

Comment 5 Jon Orris 2026-09-24 09:07:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:71419 https://access.redhat.com/errata/RHSA-2026:71419

Comment 6 Jon Orris 2026-09-24 10:58:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:71460 https://access.redhat.com/errata/RHSA-2026:71460

Comment 7 Jon Orris 2026-09-24 15:24:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:71610 https://access.redhat.com/errata/RHSA-2026:71610

Comment 8 Jon Orris 2026-09-24 15:39:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:71611 https://access.redhat.com/errata/RHSA-2026:71611

Comment 9 Jon Orris 2026-09-24 16:39:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:71487 https://access.redhat.com/errata/RHSA-2026:71487

Comment 10 Jon Orris 2026-09-25 19:24:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:72110 https://access.redhat.com/errata/RHSA-2026:72110

Comment 11 Jon Orris 2026-09-25 22:16:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:72183 https://access.redhat.com/errata/RHSA-2026:72183

Comment 12 Jon Orris 2026-09-26 17:35:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:72199 https://access.redhat.com/errata/RHSA-2026:72199

Comment 13 Jon Orris 2026-09-27 18:35:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:72264 https://access.redhat.com/errata/RHSA-2026:72264