Skip to finding
important · RCE / Privilege

A malicious DNS zone can overflow Unbound's DNSSEC digest buffer.

Affects

Unbound, a cross-platform recursive and caching DNS resolver commonly deployed on Linux and network infrastructure.

After the attacker induces a query to a controlled zone, a self-referential compression pointer makes DNSSEC validation write beyond the allocated buffer.

Detail and 2 sources

Resolver-process code execution remains unproved. NLnet Labs identifies a fixed release, but the fix was not read for a Priority Finding.

Chain to watch
Induce an affected resolver to query an attacker-controlled zone→↓Trigger the DNSSEC heap overflow→↓Establish control-flow influence under supported hardening configurations→↓Reliable control-flow hijack and process code execution are unproved.
Unverified chainReproduce across supported allocators and hardening configurations, then measure instruction-pointer control.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026