Heap Buffer Overflow in NLnet Labs Unbound DNS Resolver
CVE-2026-56416

4.8MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-56416?

A vulnerability exists in NLnet Labs Unbound where the process of constructing the canonical RDATA form for certain resource record types can lead to a heap buffer overflow. Specifically, when handling RRSIG-covered PX/RP/MINFO/SOA RRsets, the validator wrongly assumes that a second embedded domain name is present. This oversight can allow a malicious attacker running a DNSSEC-signed authoritative server to exploit a crafted record that lacks the second domain name. Consequently, 'query_dname_tolower()' can erroneously read beyond the intended memory allocation, potentially leading to severe security ramifications.

Affected Version(s)

Unbound 0 < 1.25.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.