CVE-2026-52863
published 2026-07-22CVE-2026-52863: In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view…
PriorityP333medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.26%
17.6th percentile
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.25.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.25.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory co
ghsa_unreviewed·2026-07-22
CVE-2026-52863 [MEDIUM] CWE-416 In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory co
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on
Red Hat
unbound: Unbound: Denial of service due to memory corruption under specific configurations.
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-52863 [MEDIUM] CWE-1098 unbound: Unbound: Denial of service due to memory corruption under specific configurations.
unbound: Unbound: Denial of service due to memory corruption under specific configurations.
A flaw was found in Unbound, a validating, recursive, and caching Domain Name System (DNS) resolver. When configured with specific modules and under heavy load, a memory corruption vulnerability can occur due to improper handling of view names during subquery processing. This issue could lead to a denial of service (DoS) by causing the Unbound server to crash.
Statement: This Moderate flaw in Unbound arises from memory corruption under specific, non-default configurations involving 'respip' or 'rpz' modules, subquery attachment, and 'access-control-view' when the server is under heavy load. The likelihood of a crash is low due to reliance on memory allocator behavior, but it could lead to a denial
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations. [fedora-all]
bugzilla·2026-07-30·CVSS 5.9
CVE-2026-52863 [MEDIUM] CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations. [fedora-all]
CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetca
Bugzilla
CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations.
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-52863 [MEDIUM] CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations.
CVE-2026-52863 unbound: Unbound: Denial of service due to memory corruption under specific configurations.
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view
2026-07-22
Published