Bug 2503062 (CVE-2026-40691) - CVE-2026-40691 unbound: Unbound: Denial of Service via crafted DNSCrypt query
Summary: CVE-2026-40691 unbound: Unbound: Denial of Service via crafted DNSCrypt query
Keywords:
Status: NEW
Alias: CVE-2026-40691
Deadline: 2026-07-22
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2506178
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 21:28 UTC by OSIDB Bzimport
Modified: 2026-08-31 10:17 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-20 21:28:26 UTC
A denial of service vulnerability has been discovered in Unbound when compiled with DNSCrypt support ('--enable-dnscrypt').
A single bad DNSCrypt query over TCP could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow and eventual server crash and denial of service.

Unbound 1.25.2 includes fixes to select the proper buffer TCP buffer for DNSCrypt, to properly check against the buffer's capacity and to clear the buffer before writing the dnscrypt contents otherwise UDP queries can hit assertions.


Note You need to log in before you can comment on or make changes to this bug.