Back

MEDIUM

Memory corruption could lead to crash and denial of service

Published Jul 22, 2026

Description

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

Affected products

Remediation

Vendor solution

This issue is fixed starting with version 1.25.2

Red Hat statement

This Moderate flaw in Unbound arises from memory corruption under specific, non-default configurations involving 'respip' or 'rpz' modules, subquery attachment, and 'access-control-view' when the server is under heavy load. The likelihood of a crash is low due to reliance on memory allocator behavior, but it could lead to a denial of service.

Red Hat mitigation

To mitigate this issue, avoid configuring Unbound with a combination of 'respip' or 'rpz' modules, subquery attachment features (such as respip CNAME redirection, dns64, or subnetcache), and 'access-control-view' if these functionalities are not strictly required. Disabling these specific configurations will prevent the conditions under which memory corruption can occur. Any changes to Unbound's configuration will require a service restart to take effect, which may temporarily interrupt DNS resolution services.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner NLnet Labs
Published Jul 22, 2026
Updated Jul 22, 2026
Reserved Jun 22, 2026

CISA Vulnrichment

Updated Jul 22, 2026

NVD

Status Analyzed
Modified Jul 24, 2026

Red Hat

Severity Moderate
Public date Jul 22, 2026
Bugzilla 2506141

ENISA EUVD

Assigner NLnet Labs
Published Jul 22, 2026
Updated Jul 22, 2026

GitHub

No data