Bug 2535054 (CVE-2026-81634) - CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
Summary: CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC re...
Keywords:
Status: NEW
Alias: CVE-2026-81634
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2536900
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-16 09:04 UTC by OSIDB Bzimport
Modified: 2026-09-23 13:22 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:70754 0 None None None 2026-09-23 13:22:27 UTC

Description OSIDB Bzimport 2026-09-16 09:04:41 UTC
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.

Comment 3 Jon Orris 2026-09-23 13:22:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:70754 https://access.redhat.com/errata/RHSA-2026:70754


Note You need to log in before you can comment on or make changes to this bug.