Skip to content

CVE-2026-56416 on CTRL-OS 26.05

Aliases: CVE-2026-56416

Packages: unbound

Status: In Progress

Advisory Information

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.

Updates

2026-07-27 19:41 CEST

Metadata changes:

  • Status for package unbound: “In Progress” (6adb4107d901bc4e75e7e4659d2eccdaebe38c21)

2026-07-23 23:53 CEST

Metadata changes:

  • Status for package unbound: “Plausible

2026-07-23 23:53 CEST

Metadata changes:

  • Status for package unbound: “New