Fedora Account System
Red Hat Associate
Red Hat Customer
Access of Uninitialized Pointer vulnerability in the DNSSEC validator of the Unbound DNS resolver. The flaw is caused by the use of incorrect counters when calculating write offsets for ADDITIONAL section rrsets in chase-reply messages. DNAME duplication can increase the ANSWER section count and authority filtering can decrease the AUTHORITY section count, creating an uninitialized array slot. The validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:23231 https://access.redhat.com/errata/RHSA-2026:23231
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:24365 https://access.redhat.com/errata/RHSA-2026:24365
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:24369 https://access.redhat.com/errata/RHSA-2026:24369