UBUNTU-CVE-2026-42960

Source
https://ubuntu.com/security/CVE-2026-42960
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-42960
Upstream
Downstream
Related
Published
2026-05-20T00:00:00Z
Modified
2026-06-02T20:29:12Z
Severity
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P/U:Amber CVSS Calculator
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.

References

Affected packages

Ubuntu:22.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.13.1-1ubuntu5.15

Affected versions

1.*
1.13.1-1ubuntu1
1.13.1-1ubuntu3
1.13.1-1ubuntu5
1.13.1-1ubuntu5.1
1.13.1-1ubuntu5.2
1.13.1-1ubuntu5.3
1.13.1-1ubuntu5.4
1.13.1-1ubuntu5.5
1.13.1-1ubuntu5.7
1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.10
1.13.1-1ubuntu5.11
1.13.1-1ubuntu5.12
1.13.1-1ubuntu5.13
1.13.1-1ubuntu5.14

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "libunbound8",
            "binary_version":  "1.13.1-1ubuntu5.15"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.13.1-1ubuntu5.15"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.13.1-1ubuntu5.15"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.13.1-1ubuntu5.15"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.13.1-1ubuntu5.15"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:24.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.2-1ubuntu3.8

Affected versions

1.*
1.17.1-2
1.18.0-2ubuntu1
1.18.0-2ubuntu2
1.19.1-1ubuntu1
1.19.2-1ubuntu1
1.19.2-1ubuntu3
1.19.2-1ubuntu3.1
1.19.2-1ubuntu3.2
1.19.2-1ubuntu3.3
1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.5
1.19.2-1ubuntu3.6
1.19.2-1ubuntu3.7

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "libunbound8",
            "binary_version":  "1.19.2-1ubuntu3.8"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.19.2-1ubuntu3.8"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.19.2-1ubuntu3.8"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.19.2-1ubuntu3.8"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.19.2-1ubuntu3.8"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:25.10
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.22.0-2ubuntu2.3

Affected versions

1.*
1.22.0-1ubuntu1
1.22.0-2ubuntu1
1.22.0-2ubuntu2
1.22.0-2ubuntu2.1
1.22.0-2ubuntu2.2

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "libunbound8",
            "binary_version":  "1.22.0-2ubuntu2.3"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.22.0-2ubuntu2.3"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.22.0-2ubuntu2.3"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.22.0-2ubuntu2.3"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.22.0-2ubuntu2.3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:26.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.24.2-1ubuntu2.1

Affected versions

1.*
1.22.0-2ubuntu2
1.22.0-2ubuntu4
1.24.2-1ubuntu1
1.24.2-1ubuntu2

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "libunbound8",
            "binary_version":  "1.24.2-1ubuntu2.1"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.24.2-1ubuntu2.1"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.24.2-1ubuntu2.1"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.24.2-1ubuntu2.1"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.24.2-1ubuntu2.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:Pro:14.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.22-1ubuntu4.14.04.3+esm3

Affected versions

1.*
1.4.20-1
1.4.21-1
1.4.21-1ubuntu1
1.4.21-1ubuntu2
1.4.22-1ubuntu1
1.4.22-1ubuntu2
1.4.22-1ubuntu3
1.4.22-1ubuntu4
1.4.22-1ubuntu4.14.04.1
1.4.22-1ubuntu4.14.04.2
1.4.22-1ubuntu4.14.04.3
1.4.22-1ubuntu4.14.04.3+esm1
1.4.22-1ubuntu4.14.04.3+esm2

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libunbound2",
            "binary_version":  "1.4.22-1ubuntu4.14.04.3+esm3"
        },
        {
            "binary_name":  "python-unbound",
            "binary_version":  "1.4.22-1ubuntu4.14.04.3+esm3"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.4.22-1ubuntu4.14.04.3+esm3"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.4.22-1ubuntu4.14.04.3+esm3"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.4.22-1ubuntu4.14.04.3+esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:Pro:16.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=esm-infra-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.8-1ubuntu1.1+esm3

Affected versions

1.*
1.4.22-1ubuntu6
1.5.7-1ubuntu1
1.5.7-1ubuntu2
1.5.8-1ubuntu1
1.5.8-1ubuntu1.1
1.5.8-1ubuntu1.1+esm1
1.5.8-1ubuntu1.1+esm2

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libunbound2",
            "binary_version":  "1.5.8-1ubuntu1.1+esm3"
        },
        {
            "binary_name":  "python-unbound",
            "binary_version":  "1.5.8-1ubuntu1.1+esm3"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.5.8-1ubuntu1.1+esm3"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.5.8-1ubuntu1.1+esm3"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.5.8-1ubuntu1.1+esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:Pro:18.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.7-1ubuntu2.6+esm4

Affected versions

1.*
1.6.5-1
1.6.7-1
1.6.7-1build1
1.6.7-1ubuntu1
1.6.7-1ubuntu2
1.6.7-1ubuntu2.1
1.6.7-1ubuntu2.2
1.6.7-1ubuntu2.3
1.6.7-1ubuntu2.4
1.6.7-1ubuntu2.5
1.6.7-1ubuntu2.6
1.6.7-1ubuntu2.6+esm2
1.6.7-1ubuntu2.6+esm3

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libunbound2",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        },
        {
            "binary_name":  "python-unbound",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.6.7-1ubuntu2.6+esm4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"
Ubuntu:Pro:20.04:LTS
unbound

Package

Name
unbound
Purl
pkg:deb/ubuntu/unbound?arch=source&distro=esm-infra%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.4-2ubuntu1.11+esm1

Affected versions

1.*
1.9.0-2ubuntu1
1.9.0-2ubuntu2
1.9.4-2
1.9.4-2ubuntu1
1.9.4-2ubuntu1.1
1.9.4-2ubuntu1.2
1.9.4-2ubuntu1.3
1.9.4-2ubuntu1.4
1.9.4-2ubuntu1.5
1.9.4-2ubuntu1.6
1.9.4-2ubuntu1.8
1.9.4-2ubuntu1.9
1.9.4-2ubuntu1.11

Ecosystem specific

{
    "availability":  "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries":  [
        {
            "binary_name":  "libunbound8",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        },
        {
            "binary_name":  "python-unbound",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        },
        {
            "binary_name":  "python3-unbound",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        },
        {
            "binary_name":  "unbound",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        },
        {
            "binary_name":  "unbound-anchor",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        },
        {
            "binary_name":  "unbound-host",
            "binary_version":  "1.9.4-2ubuntu1.11+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42960.json"