Skip to finding
important · DNS

A malicious DNS zone can corrupt Unbound's DNSSEC-validation heap.

Affects

Unbound, a validating recursive DNS resolver deployed on servers and network appliances.

A crafted DNSKEY makes digest processing decompress attacker-controlled data beyond its heap buffer when a vulnerable validating resolver queries the attacker's zone.

Detail and 2 sources

Code execution is possible but has not been publicly demonstrated; Unbound 1.26.1 contains the fix.

Chain to watch
Control an authoritative DNS zone and induce a resolver query.→↓Return the self-referential compressed DNSKEY and corrupt the validation heap.→↓Establish stable control-flow influence on supported builds.→↓Reliable instruction-pointer control and server-process code execution remain unproven.
Unverified chainReproduce the overflow under supported distribution and appliance allocators, then demonstrate stable control-flow influence.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026