CVE-2026-56416
published 2026-07-22CVE-2026-56416: In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it…
PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCNILAL
EPSS
0.12%
2.4th percentile
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| rhoso-operators | designate-rhel9-operator | — | — |
| rhoso | openstack-unbound-rhel9 | — | — |
| rhosp-rhel8-tech-preview | openstack-unbound | — | — |
| rhosp-rhel9 | openstack-unbound | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs Unbound up to 1.25.1 Wire Format Parser query_dname_tolower heap-based overflow (WID-SEC-2026-2492)
vuldb·2026-09-11·CVSS 4.8
CVE-2026-56416 [MEDIUM] NLnet Labs Unbound up to 1.25.1 Wire Format Parser query_dname_tolower heap-based overflow (WID-SEC-2026-2492)
A vulnerability classified as very critical was found in NLnet Labs Unbound up to 1.25.1. Impacted is the function query_dname_tolower of the component Wire Format Parser. Executing a manipulation can lead to heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-56416. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded
ghsa_unreviewed·2026-07-22
CVE-2026-56416 [MEDIUM] CWE-354 In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the def
Red Hat
unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
vendor_redhat·2026-07-22·CVSS 4.8
CVE-2026-56416 [MEDIUM] CWE-125 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of tha
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56416 netdata: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 netdata: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
CVE-2026-56416 netdata: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who r
Bugzilla
CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker w
Bugzilla
CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
CVE-2026-56416 lua-unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker
Bugzilla
CVE-2026-56416 golang-github-grpc-ecosystem-gateway-2: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 golang-github-grpc-ecosystem-gateway-2: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
CVE-2026-56416 golang-github-grpc-ecosystem-gateway-2: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the
Bugzilla
CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who
Bugzilla
CVE-2026-56416 golang-github-grpc-ecosystem-gateway: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 golang-github-grpc-ecosystem-gateway: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
CVE-2026-56416 golang-github-grpc-ecosystem-gateway: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the f
Bugzilla
CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an a
Bugzilla
CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
bugzilla·2026-07-23·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
CVE-2026-56416 ghc-unbounded-delays: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an
Bugzilla
CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
bugzilla·2026-07-22·CVSS 4.8
CVE-2026-56416 [MEDIUM] CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past
2026-07-22
Published