CVE-2026-55717
Description
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/unbound&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/unbound&distro=openSUSE%20Tumbleweed
< 1.25.2-160000.1.1+ 1 more
- (no CPE)range: < 1.25.2-160000.1.1
- (no CPE)range: < 1.25.2-1.1
Patches
Vulnerability mechanics
References
1- www.nlnetlabs.nl/downloads/unbound/CVE-2026-55717.txtnvdVendor Advisory
News mentions
1- Nlnetlabs Unbound: 23 Vulnerabilities Disclosed Together in DNSSEC, DoQ, and RPZ HandlingVypr Intelligence · Jul 23, 2026