Denial of Service and Remote Code Execution in NLnet Labs Unbound DNS Resolver
CVE-2026-33278
9.1CRITICAL
What is CVE-2026-33278?
A vulnerability in NLnet Labs' Unbound DNS resolver has been identified in versions 1.19.1 through 1.25.0, affecting the DNSSEC validator. The issue arises when the DNSSEC validator attempts to handle deep copying of data structures. An attacker could exploit this flaw by crafting a malicious signed zone and querying a vulnerable instance of Unbound. The vulnerability allows for Denial of Service due to pointer mishandling that can lead to dereferencing a dangling pointer after memory regions have been freed. The potential outcome includes application crashes or arbitrary code execution if the exploit is successfully executed. A patch addressing the issue has been implemented in Unbound version 1.25.1.
Affected Version(s)
Unbound 1.19.1 < 1.25.1
