SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55973

HIGH · CVSS 7.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions 1.23.0 to 1.25.1 are vulnerable when the 'dns-error-reporting' feature is enabled, allowing an attacker to exploit the EDNS Report-Channel option. This flaw can lead to a stack overflow, potentially causing the DNS resolver daemon to crash, which disrupts service availability. Organizations using affected versions of Unbound, particularly those with DNS error reporting enabled, should prioritize patching this vulnerability to mitigate the risk of denial-of-service attacks.

CVE
CVE-2026-55973
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.

Related CVEs

Other vulnerabilities affecting the same vendor(s)