CVE-2026-42944 Details
Description
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
A heap overflow vulnerability has been identified in NLnet Labs Unbound versions 1.14.0 prior to 1.25.0. The issue arises when multiple NSID, DNS Cookie EDNS, and EDNS Padding options are encoded in the reply packet. Exploitation requires the relevant options to be enabled. An adversary can exploit this vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field allows the encoder to overflow the available space, leading to a heap overflow write of Unbound-controlled data, causing a crash.
Users can upgrade to Unbound version 1.25.1, which includes the necessary patch. For those using Unbound 1.25.0, a specific patch is available that addresses the vulnerability. Instructions for applying this patch are included in the Unbound 1.25.0 release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:19752 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23231 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:24365 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:24369 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42944 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2479774 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42944.json | redhat-SADP | |
| https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42944.txt | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-131 | Incorrect Calculation of Buffer Size | redhat-SADP |
| CWE-197 | Numeric Truncation Error | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nlnetlabs unbound | >= 1.14.0, < 1.25.1 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | New CVE Received | [email protected] |