Use-after-free in Unbound - CVE-2026-78227
Published: September 16, 2026 / Updated: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the DNS-over-QUIC stream output buffer handling when processing a client RESET_STREAM and retransmitting a STREAM frame after a PTO timeout. A remote attacker can query the server, withhold acknowledgments, send a RESET_STREAM, and wait for a PTO timeout to cause a denial of service.
Only builds compiled with DNS-over-QUIC support using --with-libngtcp2 are vulnerable.
Affected software
Fedora
unbound
How to mitigate CVE-2026-78227
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45