Bug 2479821 (CVE-2026-42960) - CVE-2026-42960 unbound: Unbound DNS Cache Poisoning via Promiscuous Additional Section RRSet Acceptance
Summary: CVE-2026-42960 unbound: Unbound DNS Cache Poisoning via Promiscuous Additiona...
Keywords:
Status: NEW
Alias: CVE-2026-42960
Deadline: 2026-05-20
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2480119 2481462
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-19 12:13 UTC by OSIDB Bzimport
Modified: 2026-06-16 18:05 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-19 12:13:51 UTC
Acceptance of Extraneous Untrusted Data vulnerability in the DNS response scrubbing logic of the Unbound DNS resolver. The flaw allows promiscuous RRSets that complement DNS replies in the authority section to be cached when accompanied by address records in the additional section. Specifically, Unbound marks additional section address records as allowed for any authority RRSet type, not just NS records. A malicious actor can exploit this by injecting RRSets other than NS (e.g., MX) accompanied by address records via spoofed reply packets or fragmentation attacks. Unbound then accepts and caches the relative address records from the additional section if the authority RRSet has sufficient trust, enabling DNS cache poisoning.


Note You need to log in before you can comment on or make changes to this bug.