Bug 2506141 (CVE-2026-52863) - CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations.
Summary: CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption u...
Keywords:
Status: NEW
Alias: CVE-2026-52863
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509271
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-22 14:02 UTC by OSIDB Bzimport
Modified: 2026-07-30 13:14 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-22 14:02:19 UTC
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.


Note You need to log in before you can comment on or make changes to this bug.