Improper control of a resource through its lifetime in Unbound - CVE-2026-42955
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote user to extend the ghost domain window.
The vulnerability exists due to improper cache handling in the handling of cached parent-side A/AAAA glue rrsets when processing A/AAAA queries for a ghost zone. A remote user can trigger a client A/AAAA query to extend the ghost domain window.
Exploitation requires control of a ghost zone and the ability to query a vulnerable resolver. In configurations with 'harden-referral-path: yes' enabled, no client query is required because the resolver performs the query implicitly.