Heap-based buffer overflow in Unbound - CVE-2026-82717
Published: September 16, 2026 / Updated: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the CNAME synthesis packet-buffer handling logic when processing a crafted upstream DNS response that requires max TTL rewriting. A remote attacker can send a specially crafted upstream DNS response to execute arbitrary code.
Successful code execution depends on the system configuration, compilation options, and heap memory layout.
Affected software
Fedora
unbound
How to mitigate CVE-2026-82717
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45