Back

HIGH

Possible degradation of service from continuous queries on the same TCP/DoT connection

Published Sep 16, 2026

Description

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.

Affected products

Remediation

Vendor solution

This issue is fixed starting with version 1.26.1

Red Hat statement

This Moderate severity flaw in Unbound allows a remote attacker to cause a denial of service by continuously sending distinct, uncached DNS queries over a TCP or DNS-over-TLS (DoT) connection. This can monopolize a single worker's event loop, leading to service degradation for legitimate users. The impact is limited to availability and requires sustained malicious traffic.

Red Hat mitigation

To mitigate this issue, restrict network access to the Unbound DNS resolver to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Unbound service ports (e.g., TCP port 53 for DNS over TCP, TCP port 853 for DNS over TLS). For example, using `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="53" protocol="tcp" accept'` and `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="853" protocol="tcp" accept'`. After adding rules, apply them with `firewall-cmd --reload`. Replace `<TRUSTED_NETWORK>` with the IP address or network range of trusted clients. Reloading firewall rules may temporarily interrupt network connections.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NLnet Labs
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Sep 7, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity Moderate
Public date Sep 16, 2026