Impact
Unbound processes DNSSEC DNSKEY records by copying their RDATA into a digest buffer. A crafted DNSKEY that contains a compression pointer to its own RDATA can overflow this buffer, corrupting the stack or control data and enabling arbitrary code execution or denial of service. The CVE highlights that the overflow can be triggered by an attacker‑controlled zone and that remote code execution is possible through manipulated data. The impact therefore covers confidentiality, integrity, and availability of the resolver.
Affected Systems
NLnet Labs Unbound versions up to and including 1.26.0 are the affected product. Deployments are typically public or private DNS resolvers that perform DNSSEC validation and may receive queries from untrusted clients on the internet.
Risk and Exploitability
The vulnerability is exploitable remotely by any client that can supply a malicious zone file to the Unbound instance. Attack action requires control of a zone served by the resolver, which is plausible for internal or external zone administrators. Because Unbound is often exposed on the public network, the attack surface is large. The CVSS score of 9.1 indicates a high severity, while the EPSS score of less than 1% indicates a low probability of observed exploitation at this time. The vulnerability is not yet listed in the CISA KEV catalog, but its potential for remote code execution makes it a high‑risk issue that should be addressed promptly.
OpenCVE Enrichment