Bug 2535055 (CVE-2026-80225) - CVE-2026-80225 unbound: Unbound: Denial of Service via continuous queries on TCP/DoT connection
Summary: CVE-2026-80225 unbound: Unbound: Denial of Service via continuous queries on ...
Keywords:
Status: NEW
Alias: CVE-2026-80225
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2537323
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-16 09:04 UTC by OSIDB Bzimport
Modified: 2026-09-21 08:27 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-16 09:04:51 UTC
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.


Note You need to log in before you can comment on or make changes to this bug.