A severe heap overflow vulnerability in the Unbound DNS resolver, a critical piece of internet infrastructure, could allow remote attackers to execute arbitrary code on affected servers. The flaw, CVE-2026-81642, impacts every version of Unbound prior to the emergency release 1.26.1, which contains the fix.

Disclosed by maintainer NLnet Labs, the bug resides in Unbound's DNSSEC validator—a component designed to ensure DNS security. An attacker who controls a malicious DNS zone can trigger the heap overflow by querying a vulnerable Unbound resolver, creating a pathway for code execution. This compromise could allow interception, redirection, or disruption of all DNS traffic relying on the resolver, affecting enterprises, ISPs, and hosting providers.

The vulnerability presents a stark irony: the flaw exists within DNSSEC, the very protocol intended to secure DNS. This underscores the ongoing challenges in securing foundational internet systems, where security features themselves can become unexpected attack vectors.

Recommended Actions for Administrators

Network administrators must treat this as an emergency. The priority actions are:

  1. Upgrade Unbound Immediately: Deploy version 1.26.1. This is the definitive solution. Identify and update all instances of Unbound without delay.

  2. Apply a Temporary Mitigation: If an immediate upgrade is not possible, mitigate the risk by adding val-nsec3-max-iterations: 0 to the Unbound configuration. This disables the vulnerable code path at the cost of reduced DNSSEC functionality and must be followed by a full upgrade.

  3. Conduct an Audit: Systematically verify the version of Unbound across your network and confirm that the patch or workaround has been applied. The rapid release from NLnet Labs minimizes the exposure window, but action is required from operators.

The coordinated advisory and patch release exemplifies effective open-source security response, but the security of core systems ultimately depends on swift deployment by administrators.


互聯網基礎設施關鍵組件——Unbound DNS 解析器中存在一個嚴重的堆疊溢位漏洞,可能允許遠端攻擊者在受影響的伺服器上執行任意代碼。此漏洞(CVE-2026-81642)影響所有早於緊急發布的 1.26.1 版本的 Unbound 軟件,該版本已包含修復程式。

由維護者 NLnet Labs 披露的此漏洞,存在於 Unbound 的 DNSSEC 驗證器中——該組件旨在確保 DNS 安全。控制惡意 DNS 區域的攻擊者,可透過查詢受漏洞影響的 Unbound 解析器觸發堆疊溢位,從而建立代碼執行的攻擊途徑。此種入侵可能導致依賴該解析器的所有 DNS 通訊被截取、重定向或中斷,影響企業、互聯網服務供應商及託管服務商。

該漏洞的揭露充滿諷刺意味:缺陷恰恰存在於旨在保障 DNS 安全的協議 DNSSEC 之中。這凸顯了保護互聯網基礎系統所面臨的持續挑戰——安全功能本身可能成為意外的攻擊向量。

管理員建議行動

網絡管理員必須將此視為緊急事件。首要行動包括:

  1. 立即升級 Unbound: 部署 1.26.1 版本。此為根本解決方案。請識別並更新所有 Unbound 實例,切勿延遲。

  2. 採取臨時緩解措施: 若無法立即升級,可在 Unbound 配置中加入 val-nsec3-max-iterations: 0 以緩解風險。此舉會以減弱部分 DNSSEC 功能為代價,禁用存在漏洞的代碼路徑,但仍需隨後進行完整升級。

  3. 進行審計: 系統性地驗證整個網絡中 Unbound 的版本,並確認已套用補丁或變通方案。NLnet Labs 的快速發布雖縮短了漏洞暴露窗口,但運營商仍需主動採取行動。

此次協調發布的安全公告與補丁,體現了有效的開源安全應對機制,但核心系統的安全最終仍取決於管理員的迅速部署。

新聞來源 / Original News Source