Stack-based buffer overflow in Unbound - CVE-2026-55973
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in find_closest_of_type() when processing a crafted upstream DNS response containing an EDNS Report-Channel option. A remote attacker can send a specially crafted upstream response from a delegated zone they control to cause a denial of service.
The issue is reachable only when 'dns-error-reporting: yes' is enabled.