CVE-2026-55973
published 2026-07-22CVE-2026-55973: In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
37.6th percentile
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.23.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.23.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs Unbound up to 1.25.1 Iterator find_closest_of_type input validation (Nessus ID 337342 / WID-SEC-2026-2492)
vuldb·2026-08-18·CVSS 7.5
CVE-2026-55973 [HIGH] NLnet Labs Unbound up to 1.25.1 Iterator find_closest_of_type input validation (Nessus ID 337342 / WID-SEC-2026-2492)
A vulnerability was found in NLnet Labs Unbound up to 1.25.1. It has been rated as very critical. This impacts the function find_closest_of_type of the component Iterator. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2026-55973. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's
ghsa_unreviewed·2026-07-22
CVE-2026-55973 [HIGH] CWE-20 In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash(
Red Hat
unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
vendor_redhat·2026-07-22·CVSS 7.5
CVE-2026-55973 [HIGH] CWE-805 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
A flaw was found in Unbound. When the 'dns-error-reporting: yes' option is enabled, a remote attacker can send a specially crafted DNS response containing a malformed EDNS Report-Channel option from a delegated zone they control. This can lead to a stack variable overwrite, causing the Unbound daemon to terminate. This vulnerability results in a denial of service.
Statement: This Important denial of service flaw in Unbound occurs when the `dns-error-reporting` option is explicitly enabled, allowing a remote attacker to terminate the daemon with a crafted DNS response. While several Red Hat products are affected, many Red Hat Enterprise Linux and OpenShift Container Platform versions are not vulnerable as the aff
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option [fedora-all]
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-55973 [HIGH] CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option [fedora-all]
CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned length is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to se
Bugzilla
CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
bugzilla·2026-07-20·CVSS 7.5
CVE-2026-55973 [HIGH] CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
When 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned length is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the firs
2026-07-22
Published