important · RCE / Privilege
A malicious DNS zone can overflow Unbound's DNSSEC digest buffer.
Affects
Unbound, a cross-platform recursive and caching DNS resolver commonly deployed on Linux and network infrastructure.
After the attacker induces a query to a controlled zone, a self-referential compression pointer makes DNSSEC validation write beyond the allocated buffer.
Detail and 2 sources
Resolver-process code execution remains unproved. NLnet Labs identifies a fixed release, but the fix was not read for a Priority Finding.
Chain to watch
Induce an affected resolver to query an attacker-controlled zone→↓Trigger the DNSSEC heap overflow→↓Establish control-flow influence under supported hardening configurations→↓Reliable control-flow hijack and process code execution are unproved.
Unverified chainReproduce across supported allocators and hardening configurations, then measure instruction-pointer control.