A heap overflow in the Unbound DNS resolver's DNSSEC validator, affecting every release up to and including 1.26.0. NVD records it as awaiting analysis with a score of 9.1 (Critical, CVSS 4.0); the maintainer NLnet Labs rates it Critical and lists denial of service as the impact with remote code execution possible through attacker-controlled data.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-81642 |
| CVSS | 9.1 (Critical, CVSS 4.0) |
| Vendor / product | NLnet Labs / Unbound DNS resolver up to and including 1.26.0 |
| Reported | 2026-09-17 |
The overflow occurs while the validator digests a DNSKEY record whose owner name is a compression pointer into the record's own data. An attacker who controls a malicious zone and queries a vulnerable resolver triggers it, and the advisory attaches no configuration condition to the affected range. Unbound 1.26.1 fixes this and eight other flaws; standalone patches for 1.26.0 are published and tested. NLnet Labs reports no exploitation, and CISA's KEV entry marked exploitation as "none" at publication. Because Unbound is widely deployed as a recursive resolver across ISP, enterprise and distribution stacks, the patch is the operational priority β Debian had marked the fix only in unstable at the time of disclosure.