Memory corruption could lead to crash and denial of service
Published Jul 22, 2026
5.9
MEDIUMCVSS 3.1
EPSS 0.36%
Description
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.
Affected products
-
Affected
- ≥ 1.25.0, < 1.25.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NLnet Labs | Unbound | unaffected | Affected
|
No data.
Red Hat Hardened Images
unbound-main-1.25.2-0.1.hum1
Fixed · RHSA-2026:43588
Red Hat Enterprise Linux 10
unbound
Not affected
Red Hat Enterprise Linux 6
unbound
Not affected
Red Hat Enterprise Linux 7
unbound
Not affected
Red Hat Enterprise Linux 8
unbound
Not affected
Red Hat Enterprise Linux 9
unbound
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | unbound-main-1.25.2-0.1.hum1 | Fixed | RHSA-2026:43588 |
| Red Hat Enterprise Linux 10 | unbound | Not affected | n/a |
| Red Hat Enterprise Linux 6 | unbound | Not affected | n/a |
| Red Hat Enterprise Linux 7 | unbound | Not affected | n/a |
| Red Hat Enterprise Linux 8 | unbound | Not affected | n/a |
| Red Hat Enterprise Linux 9 | unbound | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed starting with version 1.25.2
Red Hat statement
This Moderate flaw in Unbound arises from memory corruption under specific, non-default configurations involving 'respip' or 'rpz' modules, subquery attachment, and 'access-control-view' when the server is under heavy load. The likelihood of a crash is low due to reliance on memory allocator behavior, but it could lead to a denial of service.
Red Hat mitigation
To mitigate this issue, avoid configuring Unbound with a combination of 'respip' or 'rpz' modules, subquery attachment features (such as respip CNAME redirection, dns64, or subnetcache), and 'access-control-view' if these functionalities are not strictly required. Disabling these specific configurations will prevent the conditions under which memory corruption can occur. Any changes to Unbound's configuration will require a service restart to take effect, which may temporarily interrupt DNS resolution services.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-52863 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506141 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47677 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-52863
- https://www.cve.org/CVERecord?id=CVE-2026-52863
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-52863.txt vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-52863 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2506141 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47677 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-52863 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-52863 | ||
| https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-52863.txt | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data