Bug 2479806 (CVE-2026-42959) - CVE-2026-42959 unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages
Summary: CVE-2026-42959 unbound: Unbound DNSSEC Validator Denial of Service via Incorr...
Keywords:
Status: NEW
Alias: CVE-2026-42959
Deadline: 2026-05-20
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2480119 2481464
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-19 11:35 UTC by OSIDB Bzimport
Modified: 2026-06-16 18:07 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:23231 0 None None None 2026-06-04 08:32:41 UTC
Red Hat Product Errata RHSA-2026:24365 0 None None None 2026-06-08 08:40:56 UTC
Red Hat Product Errata RHSA-2026:24369 0 None None None 2026-06-08 10:25:31 UTC

Description OSIDB Bzimport 2026-05-19 11:35:15 UTC
Access of Uninitialized Pointer vulnerability in the DNSSEC validator of the Unbound DNS resolver. The flaw is caused by the use of incorrect counters when calculating write offsets for ADDITIONAL section rrsets in chase-reply messages. DNAME duplication can increase the ANSWER section count and authority filtering can decrease the AUTHORITY section count, creating an uninitialized array slot. The validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records.

Comment 2 errata-xmlrpc 2026-06-04 08:32:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:23231 https://access.redhat.com/errata/RHSA-2026:23231

Comment 3 errata-xmlrpc 2026-06-08 08:40:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:24365 https://access.redhat.com/errata/RHSA-2026:24365

Comment 4 errata-xmlrpc 2026-06-08 10:25:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:24369 https://access.redhat.com/errata/RHSA-2026:24369


Note You need to log in before you can comment on or make changes to this bug.