Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52863

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 5.9

Описание

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

A flaw was found in Unbound, a validating, recursive, and caching Domain Name System (DNS) resolver. When configured with specific modules and under heavy load, a memory corruption vulnerability can occur due to improper handling of view names during subquery processing. This issue could lead to a denial of service (DoS) by causing the Unbound server to crash.

Отчет

This Moderate flaw in Unbound arises from memory corruption under specific, non-default configurations involving 'respip' or 'rpz' modules, subquery attachment, and 'access-control-view' when the server is under heavy load. The likelihood of a crash is low due to reliance on memory allocator behavior, but it could lead to a denial of service.

Меры по смягчению последствий

To mitigate this issue, avoid configuring Unbound with a combination of 'respip' or 'rpz' modules, subquery attachment features (such as respip CNAME redirection, dns64, or subnetcache), and 'access-control-view' if these functionalities are not strictly required. Disabling these specific configurations will prevent the conditions under which memory corruption can occur. Any changes to Unbound's configuration will require a service restart to take effect, which may temporarily interrupt DNS resolution services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10unboundNot affected
Red Hat Enterprise Linux 6unboundNot affected
Red Hat Enterprise Linux 7unboundNot affected
Red Hat Enterprise Linux 8unboundNot affected
Red Hat Enterprise Linux 9unboundNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesunbound-main-1.25.2-0.1.hum1FixedRHSA-2026:4358822.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1098
https://bugzilla.redhat.com/show_bug.cgi?id=2506141unbound: Unbound: Denial of service due to memory corruption under specific configurations.

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
12 дней назад

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

CVSS3: 5.9
nvd
12 дней назад

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

CVSS3: 5.9
msrc
12 дней назад

Memory corruption could lead to crash and denial of service

CVSS3: 5.9
debian
12 дней назад

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that ma ...

CVSS3: 5.9
github
12 дней назад

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

5.9 Medium

CVSS3