important · DNS
A malicious DNS zone can corrupt Unbound's DNSSEC-validation heap.
Affects
Unbound, a validating recursive DNS resolver deployed on servers and network appliances.
A crafted DNSKEY makes digest processing decompress attacker-controlled data beyond its heap buffer when a vulnerable validating resolver queries the attacker's zone.
Detail and 2 sources
Code execution is possible but has not been publicly demonstrated; Unbound 1.26.1 contains the fix.
Chain to watch
Control an authoritative DNS zone and induce a resolver query.→↓Return the self-referential compressed DNSKEY and corrupt the validation heap.→↓Establish stable control-flow influence on supported builds.→↓Reliable instruction-pointer control and server-process code execution remain unproven.
Unverified chainReproduce the overflow under supported distribution and appliance allocators, then demonstrate stable control-flow influence.