CVE-2026-33278
NLnet Labs Unbound, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A s...
- CVSS
- 9.1
- EPSS
- 1.27% 67.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.20