<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:24:29.626771+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339352</id>
    <title>EUVD-2026-339352</title>
    <updated>2026-10-03T17:24:29.654420+00:00</updated>
    <content>EUVD-2026-339352</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55990</id>
    <title>fkie_cve-2026-55990</title>
    <updated>2026-10-03T17:24:29.654463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hpr4-88jh-4pvx</id>
    <title>GHSA-hpr4-88jh-4pvx</title>
    <updated>2026-10-03T17:24:29.654507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hpr4-88jh-4pvx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-55990</id>
    <title>msrc_CVE-2026-55990 — Packet of death for a DNSCrypt misconfigured Unbound</title>
    <updated>2026-10-03T17:24:29.654573+00:00</updated>
    <content>msrc_CVE-2026-55990</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-55990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3333</id>
    <title>OESA-2026-3333 — unbound security update</title>
    <updated>2026-10-03T17:24:29.654604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: unbound</p>
<p>Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;apos;t make custom builds or provide specific features to paying customers only.

Security Fix(es):</p>
<p>With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with &amp;apos;unwanted-reply-threshold&amp;apos;, could eventually be abruptly terminated if the threshold is reached and libunbound needs to call &amp;apos;libworker_alloc_cleanup&amp;apos; since the function is absent from the function call allow list. When an application using libunbound sets &amp;apos;unwanted-reply-threshold&amp;apos; to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the &amp;apos;libworker_alloc_cleanup&amp;apos; will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function &amp;apos;worker_alloc_cleanup&amp;apos; is registed in the allow list and proceeds to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</id>
    <title>openSUSE-SU-2026:11380-1 — libunbound8-1.25.2-1.1 on GA media</title>
    <updated>2026-10-03T17:24:29.654682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libunbound8-1.25.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:43588</id>
    <title>RHSA-2026:43588 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T17:24:29.654710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to 'harden-below-nxdomain' logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:43588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</id>
    <title>SUSE-SU-2026:23050-1 — Security update for unbound</title>
    <updated>2026-10-03T17:24:29.654767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for unbound</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55990</id>
    <title>UBUNTU-CVE-2026-55990</title>
    <updated>2026-10-03T17:24:29.654791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound</p>
<p>In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</id>
    <title>WID-SEC-W-2026-2492 — Unbound: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:24:29.654826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492"/>
  </entry>
</feed>
