hacker-news · Crawled Sep 17, 2026

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Read original article ↗

AI Summary

A critical heap overflow vulnerability (CVE-2026-81642) exists in Unbound DNS resolver versions up to and including 1.26.0, which can be exploited remotely by an attacker controlling a malicious DNS zone to trigger denial of service or potentially achieve remote code execution. The vulnerability resides in the DNSSEC validator when processing a DNSKEY record with a compression pointer pointing into the record's own data. A second high-severity vulnerability (CVE-2026-82717), a heap corruption in CNAME synthesis, also affects the same versions and could lead to remote code execution under specific conditions. Both flaws are patched in Unbound 1.26.1.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.