Buffer Overflow Vulnerability in Unbound by NLnet Labs
CVE-2026-55973
7.5HIGH
What is CVE-2026-55973?
A buffer overflow vulnerability exists in NLnet Labs Unbound versions 1.23.0 through 1.25.1. When the 'dns-error-reporting' feature is enabled, improper handling of the EDNS Report-Channel option can lead to a crafted DNS response exploiting an inherent flaw. Specifically, the extraction of the agent domain from the upstream response occurs without proper validation, allowing an attacker to manipulate query names. When Unbound processes this malformed input, it incorrectly calculates label lengths, which results in writing over a stack variable, presenting a risk of daemon termination. This vulnerability highlights the importance of secure response handling in DNS services.
Affected Version(s)
Unbound 1.23.0 < 1.25.2
