Bug 2535053 (CVE-2026-77955) - CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
Summary: CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchrono...
Keywords:
Status: NEW
Alias: CVE-2026-77955
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2537311
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-16 09:02 UTC by OSIDB Bzimport
Modified: 2026-09-21 05:57 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-16 09:02:17 UTC
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.


Note You need to log in before you can comment on or make changes to this bug.