Race condition in Unbound - CVE-2026-77955

 

Race condition in Unbound - CVE-2026-77955

Published: September 16, 2026 / Updated: September 19, 2026


Vulnerability identifier: #VU150189
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77955
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause tampered zone contents to be served or stored on disk.

The vulnerability exists due to a race condition caused by asynchronous DS/DNSKEY resolution in ZONEMD validation for configured zones when validating ZONEMD-configured zones located below, but not at, a trust anchor. A remote attacker can exploit the validation window to cause tampered zone contents to become available before integrity verification completes.

When zonefile writing is enabled, data from a failed verification can persist on disk and be reloaded after restart until verification concludes again.


Affected software

Unbound
Fedora
unbound

How to mitigate CVE-2026-77955

Install security update from vendor's website.

Unbound - update to 1.26.1
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45

External References

Related Security Bulletins