{"cves":[{"id":"CVE-2026-54478","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:42.188635+00:00","description":"\nIn NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound\nlistens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the\nRFC 9018 server-cookie SipHash is computed over the proxy's wire address\ninstead of the PROXYv2-declared client. One server cookie obtained through\na given proxy node therefore validates for every PROXYv2-declared source\nbehind that node. On a UDP+proxy-protocol front, an off-path attacker can\nharvest one cookie with a single legitimate query, then replay it under any\nspoofed source and pass DNS Cookie checks that were deployed to defeat this\nin the first place.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54478","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53910","published":"2026-07-22T14:17:00","updated_at":"2026-08-31T18:15:05.038381+00:00","description":"\ndiff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow\ndue to multiple signed integer overflows in line‑mapping calculations.\nIncorrect arithmetic in mapping line ranges can result in corrupted values\nbeing used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the\napplication to allocate insufficient memory and subsequently perform\nout‑of‑bounds writes during internal processing.\nAn attacker who can control the output of the diff program used by diff3\n(e.g. via --diff-program pointing to a malicious script) can trigger\nout-of-bounds writes, resulting in a crash and potentially remote code\nexecution depending on the environment.\nThis issue has been fixed in commit\n9ff04d5b84743e331e80b589335a52c5480d1815\nNOTE:\nThe project maintainers claim that this is not a security issue. They state\nthat the worst outcome this issue can cause is a crash of diff and that it\ncannot be used to escalate privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53910","https://ubuntu.com/security/notices/USN-8692-1"],"bugs":[""],"patches":{"diffutils":["upstream: https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","upstream: https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815"]},"tags":{},"packages":[{"name":"diffutils","source":"https://ubuntu.com/security/cve?package=diffutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=diffutils","debian":"https://tracker.debian.org/pkg/diffutils","statuses":[{"release_codename":"bionic","status":"released","description":"1:3.6-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"3.13","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:3.7-3ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1:3.8-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:3.10-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:3.12-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:3.3-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1:3.3-3ubuntu0.1~esm1","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8692-1"],"notices":[{"id":"USN-8692-1","title":"GNU diffutils vulnerability","summary":"GNU diffutils could be made to crash if it received specially crafted\ninput.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-31T10:27:56.866432","description":"It was discovered that GNU diffutils incorrectly handled certain integer\narithmetic when mapping line ranges in diff3. A local attacker could\npossibly use this issue to cause diff3 to crash, resulting in a denial of\nservice.","is_hidden":false,"release_packages":{"bionic":[{"name":"diffutils","version":"1:3.6-1ubuntu0.1~esm1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.6-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra"},{"name":"diffutils-doc","version":"1:3.6-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"diffutils","version":"1:3.7-3ubuntu0.1~esm1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.7-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra"},{"name":"diffutils-doc","version":"1:3.7-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"diffutils","version":"1:3.8-0ubuntu2.1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.8-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.8-0ubuntu2.1","pocket":"security"},{"name":"diffutils-doc","version":"1:3.8-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.8-0ubuntu2.1","pocket":"security"}],"noble":[{"name":"diffutils","version":"1:3.10-1ubuntu0.1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.10-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.10-1ubuntu0.1","pocket":"security"},{"name":"diffutils-doc","version":"1:3.10-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.10-1ubuntu0.1","pocket":"security"}],"resolute":[{"name":"diffutils","version":"1:3.12-1ubuntu0.1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.12-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.12-1ubuntu0.1","pocket":"security"},{"name":"diffutils-doc","version":"1:3.12-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":"https://launchpad.net/ubuntu/+source/diffutils/1:3.12-1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"diffutils","version":"1:3.3-1ubuntu0.1~esm1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra-legacy"},{"name":"diffutils-doc","version":"1:3.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"diffutils","version":"1:3.3-3ubuntu0.1~esm1","description":"File comparison utilities","is_source":true},{"name":"diffutils","version":"1:3.3-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra-legacy"},{"name":"diffutils-doc","version":"1:3.3-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/diffutils","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53910"]}]},{"id":"CVE-2026-52863","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:42.188635+00:00","description":"\nIn NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes\nthe 'respip' and 'dns64' modules work together, creates a shallow copy of\nthe view name in effect that could lead to memory corruption if the owner\nof the original view name is jostled out when Unbound is under pressure.\nUnbound needs to be configured with one of 'respip'/'rpz' modules, together\nwith a module that can attach subqueries (respip CNAME redirection, dns64,\nsubnetcache) and a configured 'access-control-view' while Unbound is under\npressure so that joslte logic kicks in and starts dropping slow queries.\nThe subquery is getting a shallow copy of the view name and if the super\nquery which owns the view name is jostled out, memory corruption can occur.\nLikelihood of a crash is low, since it relies heavily on the underlying\nmemory allocator and the memory layout. Debug memory builds (e.g., ASAN)\nthat catch the free terminate the server.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-52863","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50252","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:46.767884+00:00","description":"\nIn NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is\nrandomized and intended to serve as a secret value that increases the\nentropy of DNS transactions. When resolver load balancing policies depend\non the source port while their outcome is revealed this secrecy is\nundermined. The vulnerability arises when the load balancing policy is\nconsistent with respect to the incoming source UDP port and IP address\nwhile heavily depending on the incoming source UDP port as a randomization\nsource. When the SO_REUSEPORT configuration option is enabled\n('so-reuseport: yes') in Unbound (by default), it meets these conditions,\nmaking it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound\nrandomly partitions the available UDP source port space into disjoint\nsubsets of (almost) equal size, assigning each subset to a specific worker\nthread. When an incoming DNS query is received, the kernel’s SO_REUSEPORT\nload balancing mechanism deterministically assigns the query to a socket\nassociated with a particular thread. All outgoing DNS queries generated\nduring the resolution of that request use source ports selected exclusively\nfrom the port subset assigned to the corresponding thread. Since these port\nsubsets are disjoint across threads, the source port observed in a\nresolver’s outgoing query to an authoritative name server serves as a\nreliable indicator of the worker thread that processed the original client\nquery. A malicious actor can acquire the mapping between incoming UDP\nsource ports (for a given fixed source IP address) and Unbound worker\nthreads and leverage it to conduct DNS cache poisoning attacks by\neffectively lowering the random port population per thread.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.3,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/U:Amber","baseMetrics":{"exploitabilityMetrics":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},"baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50252","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50251","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:55.716567+00:00","description":"\nIn NLnet Labs Unbound up to and including version 1.25.1, when\n'unwanted-reply-threshold' is enabled (set to any value greater than zero),\nglue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can\ndirect such traffic, by issuing DNS queries and receiving seemingly\nunwanted replies since the remote IP does not match the original source IP\nof 0.0.0.0/::0. This behavior keeps on looping for the glue records and\npushing the counter to the configured 'unwanted-reply-threshold' that\ntriggers a defensive cache clear. A malicious actor who controls a\ndelegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the\ncounter to the limit of 'unwanted-reply-threshold' to the threshold and\ntrigger a cache clean of the message and rrset caches; at will,\nindefinitely, without sending a single spoofed packet. The iterator uses\nthe 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel\nroutes the datagram over loopback), Unbound's own listener answers from\n127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this\nexample, Unbound accounts the reply as an unwanted (probably spoofed)\nanswer. The counter resets to zero on every cache flush, so the attack\nloops forever.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50251","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50248","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:50.775062+00:00","description":"\nIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz\nzone has a configured primary hostname that resolves to BOGUS A/AAAA, it is\nstill considered as a possible XFR endpoint. A malicious actor that can\nspoof the hostname's A/AAAA record (no valid RRSIG required) becomes the\nzone's XFR primary and can replaces the entire zone/the resolver's entire\nresponse policy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50248","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50243","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:50.775062+00:00","description":"\nIn NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is\nconfigured with the 'respip' module in front of the validator together with\na 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the\nrewriting handler does not check the security status of the upstream answer\nand can instead rewrite a BOGUS A/AAAA answer to point to an operator's\nconfigured IP. If the validator finds an expired or otherwise invalid RRSIG\non an answer whose A record falls within a 'response-ip'/RPZ configuration,\nthe answer is still rewritten and given a hard coded security level of\nINSECURE. This results in the client receiving an INSECURE NOERROR reply\nrewritten by the operator's configured IP. A malicious actor can exploit\nthe possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls\ninside the operator's configured subnet rewrites. Such DNSSEC protected\nanswers are then insecurely redirected to the operator's configured target.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50243","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50046","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:46.767884+00:00","description":"\nIn NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server\nname used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's\n('serviced_query') lifetime but also referenced by another struct\n('waiting_tcp'). When the owning struct is jostled out of the mesh while\nthe DoT TCP stream is still handshaking it frees the storage behind the\nreferenced string and if the TLS stream then errors out, it dereferences\nthe freed pointer. The dereference is read-only and the practical impact is\na daemon crash resulting in denial of service. A malicious actor that knows\na DoT forwarding/stub Unbound's configuration could exploit the\nvulnerability by quering records in the appropriate zone while keeping\nUnbound uder pressure so that the jostle logic kicks in. If answers for the\nvulnerable zone are slow, the likelihood of jostling such queries is\nhigher, although the timing of the jostle needs to be precise. Requirements\nfor a vulnerable Unbound is the existence of a stub/forward zone configured\nfor DoT together with a configured '#authname' suffix on the server\nidentification. The connectivity to the server needs to exhibit a transient\nfailure at the correct time in order to kick off the vulnerable error path.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50046","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50045","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:50.775062+00:00","description":"\nIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client\nquery for a deeply nested name under a DNSSEC-signed parent can cause\nUnbound to send more upstream packets per client query than the configured\n'max-global-quota'. This effectively bypasses a security configuration that\nlimits upstream amplification traffic.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50045","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46582","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:27.091403+00:00","description":"\nIn NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a\nwildcard rrset as another piece of data, could be briefly considered DNSSEC\nsecure based only on the RRSIG validation and stored into cache, before\nlater validation treats it as bogus based on NSEC validation. When the\nresolving thread puts secure on the rrset, and another thread that is on\nthe serve expired path then picks up the updated rrset contents with the\nsecure status for a reply, it can be used to change a specific record, next\nto a wildcard that could be covered by the wildcard, into the wildcard. A\nmalicious actor can exploit the possible poisonous effect by having any\nDNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper\nrecord that points to a record next to a wildcard (that could be covered by\nthe wildcard). Then quering Unbound for the wildcard sibling record would\nseed the secure message. A later (after expiry) query for the CNAME wrapper\nwould need to resolve the target sibling record. If the wildcard replay is\ninjected into the response, the wildcard rrset will update the expired\nsibling record with a secure status before completing proper wildcard\nvalidation with NSEC records and eventually treating the CNAME wrapper\nanswer as bogus. The updated poisoned rrset is now secure and points to the\nwildcard. This vulnerability is explicit for the serve expired path and\nneeds injection of the signed wildcard rrset without the NSEC accompanying\nrrset.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46582","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44690","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:23.016421+00:00","description":"\nIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient\nvalidation of the RRSIG.Labels field combined with premature cache writes\nduring RFC 8198 aggressive NSEC processing leads to cache poisoning that\npermits a malicious actor controlling a single delegated zone to poison\narbitrary sibling zones under NSEC-signed parent domains. A malicious actor\nwith one registered domain under an NSEC-signed TLD can serve malicious\ninsecure DNS responses for unrelated sibling domains (sharing the same\nparent zone). Arbitrary delegations that do not exist under the parent\ndomain and are covered by the parent's NSEC chain can be brought into\ninsecure existence by fraudulent wildcard DS records (less labels than\nexpected, unknown algorithm) from the malicious sibling domain. This allows\nthe malicious actor to inject insecure wildcard records for those\ndelegations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44690","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44687","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:31.692781+00:00","description":"\nIn NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward\nzones where the name is below an intermediate labed below a DNSSEC signed\nzone could be shadowed by the intermediate label's secure NXDOMAIN answer\nfrom the parent. This is caused by an off-by-one error in\n'harden-below-nxdomain' logic; enabled by default. It effectively bypasses\nthe configuration and the configured stub/forward zone is never contacted.\n'harden-below-nxdomain' does an upward DNS cache walk together with a\ndelegation point guard that does not allow NXDOMAIN synthesis above\nstub/forward zones. The guard tests the domain name but before stripping a\nlabel. This results in an iteration where the domain name equals the\nconfigured stub/forward zone apex that passes the guard, strips one more\nlabel, and probes the cache at the apex's immediate public parent. If that\nparent has a cached DNSSEC-secure NXDOMAIN, which it will for any private\nnamespace nested two or more labels under a signed public name, the walk\nreturns it and the configured stub/forward upstream is never contacted.\nThis can only be triggered by the query for the intermediate label (between\nthe stub/forward apex and the DNSSEC parent zone).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44687","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44621","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:23.016421+00:00","description":"\nWith NLnet Labs Unbound up to and including version 1.25.1, applications\nusing libunbound and configured with 'unwanted-reply-threshold', could\neventually be abruptly terminated if the threshold is reached and\nlibunbound needs to call 'libworker_alloc_cleanup' since the function is\nabsent from the function call allow list. When an application using\nlibunbound sets 'unwanted-reply-threshold' to any non-zero value and the\niterator queries an authoritative that replies with enough\nwrong-transaction-ID UDP datagrams to cross the threshold, the\n'libworker_alloc_cleanup' will eventually be called. Since the function is\nabsent from the function call allow list, this leads to a fatal exit of\nlibunbound and eventual termination of the embedding application.Unbound\nitself is not affected since its relevant function 'worker_alloc_cleanup'\nis registed in the allow list and proceeds to perform the documented cache\nflush.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44621","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42955","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:18.934615+00:00","description":"\nIn NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar\nvulnerability as with CVE-2026-40622 in the 'ghost domain names' family of\nattacks was found in Unbound that could extend the ghost domain window by\nup to one cached TTL configured value for A/AAAA glue records. Similar to\nother 'ghost domain names' attacks, an adversary needs to control a (ghost)\nzone and be able to query a vulnerable Unbound. A single client A/AAAA\nquery can cause Unbound to overwrite the cached expired parent-side glue\nrrset and essentially extend the ghost domain window by up to one cached\nTTL configured value ('cache-max-ttl'). In configurations where\n'harden-referral-path: yes' is used (non-default configuration), no client\nquery is required since Unbound implicitly performs that query. This is a\nvariant of CVE-2026-40622 which only addressed the NS query.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42955","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41637","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:27.091403+00:00","description":"\nIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated\nDNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting\nin low-cost inflation of the waiting number of replies for already\nin-flight resolution queries. This results in degradation of resolution\nservice for new clients for already in-flight queries. A malicious actor\ncan exploit the vulnerability by issuing DoQ queries for query names that\nneed resolution and proceeding on immediately terminating the query by one\nof STOP_SENDING/RESET_STREAM/CONNECTION_CLOSE QUIC frames. Those terminated\nDoQ queries are not properly counted for and keep inflating the number of\nwaiting replies for in-flight queries. When the maximum is reached, it\nresults in silent query drops for new clients needing resolution for\nalready in-flight queries. This vulnerability needs Unbound to be compiled\nwith DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured\nfor the listening interfaces. Additionally, a malicious actor needs access\nto multiple source IPs to bypass the by-default configured 'wait-limit'\noption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41637","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-40691","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:27.091403+00:00","description":"\nIn Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is\nreceived over TCP, the routine that encrypts the reply in place fails to\nbound the reply length against the destination buffer size. The size clamp\nthat protects the UDP path is not applied on the TCP path, so a reply\nlarger than 65504 bytes is shifted forward by 48 bytes inside a buffer of\ncapacity equal to 'msg-buffer-size', writing past the end of the heap\nallocation. A single malicious encrypted query crashes the resolver and\nlead to denial of service. This vulnerability needs Unbound to be compiled\nwith DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to\nbe configured and enabled for the listening interfaces.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-40691","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-32665","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:31.692781+00:00","description":"\nIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream\nDNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a\nnew QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size'\ngate entirely, and large input buffers are allocated later, after only the\n2-byte length prefix has been received from the initial streams. As a\nresult, a remote client can make Unbound exceed the configured 'quic-size'\nlimit with low-cost input. Using only one connection and two streams, each\nsending a declared 65535-byte length prefix and then holding the streams\nopen, a client can already trivially make Unbound roughly allocate double\nthat amount. This is a remote availability issue / memory-accounting bypass\nin the downstream DoQ implementation that leads to denial of service for\nnew DoQ clients. This vulnerability needs Unbound to be compiled with DoQ\nsupport ('--with-libngtcp2') and the 'quic-port' to be configured for the\nlistening interfaces.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32665","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16560","published":"2026-07-22T14:17:00","updated_at":"2026-08-07T01:59:54.414211+00:00","description":"\nA heap-buffer-overflow flaw was found in Directory Server (389-ds-base).\nWhen a DN contains a legacy-quoted value, the server won't close the heap\nallocation allowing another call to refer to the same memory pointer\ncausing a denial of service or an arbitrary memory write operation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16560","https://bugzilla.redhat.com/show_bug.cgi?id=2506102"],"bugs":[""],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14586","published":"2026-07-22T14:17:00","updated_at":"2026-08-06T23:45:27.091403+00:00","description":"\nIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC\nenvironments, with high concurrency and under pressure, an assertion in\nlibngtcp2 about monotonic timestamps could trigger and result in server\ntermination and thus denial of service. When interfacing with libngtcp2,\nfor DNS-over-QUIC support in Unbound, it is expected to use monotonic time.\nUnbound was using realtime instead, and in DoQ environments with high\nconcurrency and under pressure, an assert in libngtcp2 for the quic\ntimestamp would trigger and terminate the server.This vulnerability needs\nUnbound to be compiled with DoQ support ('--with-libngtcp2') and the\n'quic-port' to be configured for the listening interfaces.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14586","https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16473","published":"2026-07-22T11:16:00","updated_at":"2026-08-06T23:45:27.091403+00:00","description":"\nA flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error\nin the SBC frame decoder allows a crafted audio payload to trigger a\none-byte heap out-of-bounds read. This could allow an adjacent attacker\nstreaming Bluetooth audio to read a single byte of adjacent heap memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16473"],"bugs":[""],"patches":{"sbc":[]},"tags":{},"packages":[{"name":"sbc","source":"https://ubuntu.com/security/cve?package=sbc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sbc","debian":"https://tracker.debian.org/pkg/sbc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":6800,"limit":20,"total_results":79316}