{"id":"CVE-2026-81642","title":"In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs","summary":"In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression po…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"nlnetlabs","product":"unbound","affected":["unbound < 1.26.1"],"patched":["unbound 1.26.1"],"published":"2026-09-16","updated":"2026-09-22","sourceUpdated":"2026-09-22T18:59:21.953","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81642","references":[{"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt","label":"sep@nlnetlabs.nl"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81642.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81642"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535059"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81642"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81642"},{"url":"https://access.redhat.com/errata/RHSA-2026:68590"},{"url":"https://access.redhat.com/errata/RHSA-2026:70754"},{"url":"https://access.redhat.com/errata/RHSA-2026:71459"},{"url":"https://access.redhat.com/errata/RHSA-2026:71419"},{"url":"https://access.redhat.com/errata/RHSA-2026:71610"},{"url":"https://access.redhat.com/errata/RHSA-2026:71611"},{"url":"https://access.redhat.com/errata/RHSA-2026:71460"},{"url":"https://access.redhat.com/errata/RHSA-2026:71487"},{"url":"https://access.redhat.com/errata/RHSA-2026:72183"},{"url":"https://access.redhat.com/errata/RHSA-2026:72110"},{"url":"https://access.redhat.com/errata/RHSA-2026:72199"}],"tags":["nvd","exploit-available","cve.org","csaf","vex","red-hat"],"epss":0.00962,"epssPercentile":0.601,"exploits":{"github":1,"githubRepos":["https://github.com/suominen/CVE-2026-81642"],"checkedAt":"2026-09-27T10:34:01.880Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-16T14:30:20.298477Z"},"scores":{"nvd":9.8,"cna":9.1,"vendor":9.8},"ingestedAt":"2026-09-16T08:52:29.598Z","slug":"CVE-2026-81642","body":"## Overview\n\nIn NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.\n\n## Affected\n\n- `unbound < 1.26.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unbound 1.26.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Critical · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-26 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81642.json)\n- **RHSA-2026:68590** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68590)\n- **RHSA-2026:70754** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70754)\n- **RHSA-2026:71459** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71459)\n- **RHSA-2026:71419** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71419)\n- **RHSA-2026:71610** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71610)\n- **RHSA-2026:71611** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71611)\n- **RHSA-2026:71460** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71460)\n- **RHSA-2026:71487** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71487)\n- **RHSA-2026:72183** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:72183)\n- **RHSA-2026:72110** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:72110)\n- **RHSA-2026:72199** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-09-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:72199)","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":209311,"id":"CVE-2026-81642","ts":1790104191138,"field":"cvss","old":"9.1","new":"9.8"},{"seq":207759,"id":"CVE-2026-81642","ts":1789838304073,"field":"exploit_available","old":"false","new":"true"}]}