Use-after-free in Unbound - CVE-2026-44608
Published: May 20, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in RPZ zone handling when processing an RPZ XFR reload concurrently with reads of an RPZ zone using 'rpz-nsip' or 'rpz-nsdname' triggers. A remote attacker can trigger a crafted zone transfer timing condition to cause a denial of service.
Only multi-threaded deployments are affected, and local RPZ files do not trigger the vulnerability.