Possible degradation of service from continuous queries on the same TCP/DoT connection
Published Sep 16, 2026
7.5
HIGHCVSS 3.1
EPSS 0.48%
Description
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.
Affected products
-
- Version 0StatusaffectedConstraints<1.26.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NLnet Labs | Unbound | unaffected |
|
No data.
Red Hat Hardened Images
unbound-main-1.26.1-1.hum1
Fixed · RHSA-2026:68590
Red Hat Enterprise Linux 10
unbound
Fix deferred
Red Hat Enterprise Linux 6
unbound
Out of support scope
Red Hat Enterprise Linux 7
unbound
Fix deferred
Red Hat Enterprise Linux 8
unbound
Fix deferred
Red Hat Enterprise Linux 9
unbound
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | unbound-main-1.26.1-1.hum1 | Fixed | RHSA-2026:68590 |
| Red Hat Enterprise Linux 10 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | unbound | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | unbound | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed starting with version 1.26.1
Red Hat statement
This Moderate severity flaw in Unbound allows a remote attacker to cause a denial of service by continuously sending distinct, uncached DNS queries over a TCP or DNS-over-TLS (DoT) connection. This can monopolize a single worker's event loop, leading to service degradation for legitimate users. The impact is limited to availability and requires sustained malicious traffic.
Red Hat mitigation
To mitigate this issue, restrict network access to the Unbound DNS resolver to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Unbound service ports (e.g., TCP port 53 for DNS over TCP, TCP port 853 for DNS over TLS). For example, using `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="53" protocol="tcp" accept'` and `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="853" protocol="tcp" accept'`. After adding rules, apply them with `firewall-cmd --reload`. Replace `<TRUSTED_NETWORK>` with the IP address or network range of trusted clients. Reloading firewall rules may temporarily interrupt network connections.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-80225 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2535055 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-80225
- https://www.cve.org/CVERecord?id=CVE-2026-80225
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-80225.txt vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-80225 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2535055 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-80225 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-80225 | ||
| https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-80225.txt | vendor-advisory |
Change history (0)
No recorded changes yet.