CVE-2026-42944

7.5

NLnet Labs · Unbound

NLnet Labs Unbound versions 1.14.0 through 1.25.1 are susceptible to an out-of-bounds write caused by a numeric truncation error, potentially leading to denial-of-service.

Executive summary

A critical vulnerability in NLnet Labs Unbound versions 1.14.0 through 1.25.1 allows unauthenticated attackers to trigger an out-of-bounds write, resulting in service disruption.

Vulnerability

This vulnerability stems from a numeric truncation error (CWE-197) leading to an out-of-bounds write (CWE-787). The vulnerability is network-accessible and requires no authentication to trigger by an external party.

Business impact

Exploitation of this vulnerability poses a severe risk to DNS service availability. By triggering an out-of-bounds write, an attacker can crash the Unbound process, leading to a denial-of-service for all clients utilizing the resolver, which significantly impacts organizational network operations.

Remediation

Immediate Action: Upgrade NLnet Labs Unbound to version 1.25.1 or later to resolve the underlying memory management defect.

Proactive Monitoring: Monitor Unbound service logs for abnormal termination events and verify that process monitoring tools are correctly alerting on service outages.

Compensating Controls: Implement network-level rate limiting or ingress filtering to restrict traffic to the DNS resolver, which may reduce the likelihood of successful exploitation attempts by untrusted sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that this vulnerability shares the same fix version and risk profile as other recent Unbound issues, it should be treated with high urgency. Administrators must update to 1.25.1 to ensure the integrity and availability of their DNS services.

More NLnet Labs CVEs