CVE detail
CVE-2026-42944
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversary who can query Unbound can exploit the vulnerability by attaching multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options to the query. A flaw in the size calculation of the EDNS field truncates the correct value which allows the encoder to overflow the available space when writing. Those two combined lead to a heap overflow write of Unbound controlled data and eventually a crash. Unbound 1.25.1 contains a patch with a fix to de-duplicate the EDNS options and a fix to prevent truncation of the EDNS field size calculation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
Information published.
vendormsrc.microsoft.comMay 21, 2026, 8:03 AM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42944.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 20, 2026, 10:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2479774bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 20, 2026, 10:16 AM - https://access.redhat.com/security/cve/CVE-2026-42944access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:24369access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:24365access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:23231access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 10:16 AM - https://access.redhat.com/errata/RHSA-2026:19752access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 10:16 AM - https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42944.txtwww.nlnetlabs.nl
No excerpt available.
Vendor Advisorywww.nlnetlabs.nlMay 20, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-6679CVSS 8.8 · High
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when co…
- CVE-2026-6039CVSS 5.4 · Medium
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was trunc…
- CVE-2022-42475CVSS 9.8 · Critical
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier a…
- CVE-2026-40691CVSS 7.5 · High
In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the d…
- CVE-2019-25042CVSS 9.8 · Critical
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable…
- CVE-2019-25035CVSS 9.8 · Critical
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running…