Impact
Unbound, a DNS resolver that performs DNSSEC validation, contains a heap buffer overflow in its digest processing of DNSKEY records. When a DNSKEY includes a compression pointer that references its own RDATA, the digest buffer overflows, corrupting memory and potentially allowing arbitrary code execution or denial of service. The CVE explicitly states that attacker‑controlled data can trigger this overflow, leading to remote code execution.
Affected Systems
Unbound releases up to and including version 1.26.0 are affected. Deployments that act as DNS resolvers—whether public or private—running any of those versions are at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity flaw, while the EPSS score of < 1 % suggests a low but nonzero probability of observed exploitation. The vulnerability is exposed to any external client that can query the resolver with malicious zone data. Based on the description, it is inferred that the attacker must control a zone that the resolver validates in order to supply the crafted DNSKEY and trigger the overflow. As Unbound is often exposed on the public network, the attack surface is large. The likely attack vector is a remote query from an attacker who can serve a malicious zone to the resolver. The flaw is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA
Ubuntu USN