Vulnerability Description
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-81634?
CVE-2026-81634 is a vulnerability with a CVSS score of 7.5 (HIGH). In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by miss...
How severe is CVE-2026-81634?
CVE-2026-81634 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81634?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.