importantSYS.SOURCE: The Hacker News• 2026-09-17T18:00:00+05:30
Critical Heap Overflow in Unbound DNSSEC Validator Enables Remote Code Execution
A critical heap overflow vulnerability (CVE-2026-81642) in the Unbound DNSSEC validator could enable remote code execution (RCE) via a malicious DNS zone, according to NLnet Labs. The flaw was addressed in Unbound 1.26.1, with no reported exploitation as of the advisory release.
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with
*** END OF TRANSMISSION ***