Race condition in Unbound - CVE-2026-77955
Published: September 16, 2026 / Updated: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause tampered zone contents to be served or stored on disk.
The vulnerability exists due to a race condition caused by asynchronous DS/DNSKEY resolution in ZONEMD validation for configured zones when validating ZONEMD-configured zones located below, but not at, a trust anchor. A remote attacker can exploit the validation window to cause tampered zone contents to become available before integrity verification completes.
When zonefile writing is enabled, data from a failed verification can persist on disk and be reloaded after restart until verification concludes again.
Affected software
Fedora
unbound
How to mitigate CVE-2026-77955
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45