Heap-based buffer overflow in Unbound - CVE-2026-82717

 

Heap-based buffer overflow in Unbound - CVE-2026-82717

Published: September 16, 2026 / Updated: September 19, 2026


Vulnerability identifier: #VU150194
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-82717
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the CNAME synthesis packet-buffer handling logic when processing a crafted upstream DNS response that requires max TTL rewriting. A remote attacker can send a specially crafted upstream DNS response to execute arbitrary code.

Successful code execution depends on the system configuration, compilation options, and heap memory layout.


Affected software

Unbound
Fedora
unbound

How to mitigate CVE-2026-82717

Install security update from vendor's website.

Unbound - update to 1.26.1
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45

External References

Related Security Bulletins