<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:25:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-339648</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339648</link>
      <description>EUVD-2026-339648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339648</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50046</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50046</link>
      <description>&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50046</guid>
    </item>
    <item>
      <title>GHSA-fg9v-m7xf-p865</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fg9v-m7xf-p865</link>
      <description>&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fg9v-m7xf-p865</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-50046 — Possible heap use-after-free in an error path when a DoT forwarded query is jostled out</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50046</link>
      <description>msrc_CVE-2026-50046</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-50046</guid>
    </item>
    <item>
      <title>OESA-2026-3434 — unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3434</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the &amp;amp;apos;ghost domain names&amp;amp;apos; family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other &amp;amp;apos;ghost domain names&amp;amp;apos; attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value (&amp;amp;apos;cache-max-ttl&amp;amp;apos;). In configurations where &amp;amp;apos;harden-referral-path: yes&amp;amp;apos; is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.(CVE-2026-42955)&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the &amp;amp;apos;ghost domain names&amp;amp;apos; family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other &amp;amp;apos;ghost domain names&amp;amp;apos; attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value (&amp;amp;apos;cache-max-ttl&amp;amp;apos;). In configurations where &amp;amp;apos;harden-referral-path: yes&amp;amp;apos; is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.(CVE-2026-42955)&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3434</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11380-1 — libunbound8-1.25.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</link>
      <description>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</guid>
    </item>
    <item>
      <title>RHSA-2026:43588 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:43588</link>
      <description>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:43588</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23050-1 — Security update for unbound</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</link>
      <description>&lt;p&gt;Security update for unbound&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for unbound&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50046</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50046</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct&amp;#39;s (&amp;#39;serviced_query&amp;#39;) lifetime but also referenced by another struct (&amp;#39;waiting_tcp&amp;#39;). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound&amp;#39;s configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured &amp;#39;#authname&amp;#39; suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50046</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2492 — Unbound: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</guid>
    </item>
  </channel>
</rss>
