MGASA-2026-0451

Source
https://advisories.mageia.org/MGASA-2026-0451.html
Import Source
https://advisories.mageia.org/MGASA-2026-0451.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0451
Upstream
CVE (34)
Published
2026-09-25T05:02:40Z
Modified
2026-09-25T05:34:21Z
Summary
Updated unbound packages fixes security vulnerabilities
Details

Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY Possible heap buffer overflow during DNSSEC canonicalization CNAME synthesis could lead to heap corruption Possible ZONEMD verification bypass window Use-after-free in DoQ stream output buffer on reset re-transmission Possible degradation of service from continuous queries on the same TCP/DoT connection Use-after-free in DoH stream cleanup code path Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC 'serve-expired' can bypass Unbound 'wait-limit' Remote DNS-over-QUIC denial of service due to 'quic-size' budget bypass Packet of death for DNSCrypt over TCP Cross-zone wildcard cache poisoning via RRSIG.labels manipulation 'dns-error-reporting: yes' leads to stack buffer overflow Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated 'max-global-quota' reset by DNSSEC validation restarts Possible heap use-after-free in an error path when a DoT forwarded query is jostled out 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL BOGUS configured primary hostname accepted for XFR in auth/rpz zones Date: Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush Possible cache poisoning attack by mapping source port population per thread Memory corruption could lead to crash and denial of service 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash Packet of death for a DNSCrypt misconfigured Unbound Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path DNS Cookie bypass when combined with proxy-protocol use Privacy/configuration issue when adding local data in views through 'unbound-control' Possible arbitrary code execution during DNSSEC validation Heap overflow with multiple NSID, COOKIE, PADDING EDNS options Crash during DNSSEC validation of malicious content Date: Packet of death with DNSCrypt Another "ghost domain names" attack variant Long list of incoming EDNS options degrades performance Jostle logic bypass degrades resolution performance Degradation of service with unbounded NSEC3 hash calculations Possible cache poisoning via promiscuous records for the authority section Unbounded name compression in certain cases causes degradation of service Use after free and crash under special conditions in RPZ code Possible domain hijacking via promiscuous records in the authority section Cache poisoning via the ECS-enabled Rebirthday Attack Unbounded name compression could lead to Denial of Service Unbound vulnerable to the "DNSBomb" pulsing DoS amplification attack Denial of service when trimming EDE text on positive replies DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers NSEC3 closest encloser proof can exhaust CPU Non-Responsive Delegation Attack Novel "ghost domain names" attack by updating almost expired delegation information Novel "ghost domain names" attack by introducing subdomain delegations Local symlink attack Vulnerability in Domain Parse NXNSAttack Vulnerability in IPSEC module Vulnerability in parsing NOTIFY queries Vulnerability in the processing of wildcard synthesized NSEC records No limit to delegation chaining Ghost domain names attack Incorrect proof processing for NSEC3-signed zone Processing of duplicate CNAME records in a signed zone Empty error packet handling assertion failure

References
Credits

Affected packages

Mageia:10 / unbound

Package

Name
unbound
Purl
pkg:rpm/mageia/unbound?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.1-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0451.json"

Mageia:9 / unbound

Package

Name
unbound
Purl
pkg:rpm/mageia/unbound?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.1-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0451.json"