Bug 2480131 (CVE-2026-42534) - CVE-2026-42534 unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic
Summary: CVE-2026-42534 unbound: Unbound: Denial of Service due to degraded resolution...
Keywords:
Status: NEW
Alias: CVE-2026-42534
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2491795
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-20 10:01 UTC by OSIDB Bzimport
Modified: 2026-07-09 12:48 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:36320 0 None None None 2026-07-07 16:03:50 UTC
Red Hat Product Errata RHSA-2026:36777 0 None None None 2026-07-08 16:10:24 UTC
Red Hat Product Errata RHSA-2026:37282 0 None None None 2026-07-09 12:48:25 UTC

Description OSIDB Bzimport 2026-05-20 10:01:38 UTC
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended.

Comment 2 errata-xmlrpc 2026-07-07 16:03:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:36320 https://access.redhat.com/errata/RHSA-2026:36320

Comment 3 errata-xmlrpc 2026-07-08 16:10:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:36777 https://access.redhat.com/errata/RHSA-2026:36777

Comment 4 errata-xmlrpc 2026-07-09 12:48:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:37282 https://access.redhat.com/errata/RHSA-2026:37282


Note You need to log in before you can comment on or make changes to this bug.