Fault in Unbound DNS Resolver by NLnet Labs Leading to Service Degradation
CVE-2026-56444
What is CVE-2026-56444?
The Unbound DNS resolver, specifically versions 1.20.0 through 1.25.1, has a flaw that affects systems configured with 'serve-expired: yes' and a misconfigured 'serve-expired-client-timeout' in relation to 'discard-timeout'. In scenarios where the discard-timeout is greater than the serve-expired-client-timeout, the resolver fails to properly manage the counter for reply addresses. This mismanagement can lead to silence drop-offs for new clients making similar queries, severely affecting DNS resolution performance. An attacker may exploit this by issuing queries to a client-controlled DNS zone, potentially overwhelming the resolver and causing a significant degradation of service, thus impacting users reliant on DNS resolution.
Affected Version(s)
Unbound 1.20.0 < 1.25.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
