Inefficient Algorithmic Complexity in Unbound - CVE-2026-85501
Published: September 16, 2026 / Updated: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the DNSSEC validator's Zone, Algo, KeyTag matching mechanism when processing DNS responses containing numerous mismatched DNSKEY, RRSIG, and DS records. A remote attacker can provide a crafted DNS response to cause a denial of service.
Affected software
Fedora
unbound
How to mitigate CVE-2026-85501
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45