SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-56416

MEDIUM · CVSS 4.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions up to and including 1.25.1 are vulnerable to a heap buffer overflow when processing specific DNS records (PX/RP/MINFO/SOA) due to improper validation of embedded domain names. An attacker controlling a DNSSEC-signed authoritative server can exploit this flaw to manipulate memory, potentially leading to arbitrary code execution or crashes. Organizations using affected versions of Unbound, especially those handling DNSSEC, should prioritize patching to mitigate this risk.

CVE
CVE-2026-56416
Severity
MEDIUM
CVSS
4.8
EPSS
0.12%

Original NVD Description

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.

Related CVEs

Other vulnerabilities affecting the same vendor(s)