Bug 2506137 (CVE-2026-56416) - CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
Summary: CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC re...
Keywords:
Status: NEW
Alias: CVE-2026-56416
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2506414 2506415 2506416 2506417 2506418 2506419 2506420 2506421
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-22 14:02 UTC by OSIDB Bzimport
Modified: 2026-08-31 13:31 UTC (History)
43 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-22 14:02:03 UTC
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.


Note You need to log in before you can comment on or make changes to this bug.