Allocation of Resources Without Limits or Throttling Affecting unbound package, versions <0:1.25.2-0.1.hum1


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-UNBOUND-18339583
  • published28 Jul 2026
  • disclosed22 Jul 2026

Introduced: 22 Jul 2026

NewCVE-2026-32665  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade RHEL:10 unbound to version 0:1.25.2-0.1.hum1 or higher.
This issue was patched in RHSA-2026:43588.

NVD Description

Note: Versions mentioned in the description apply only to the upstream unbound package and not the unbound package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two streams, each sending a declared 65535-byte length prefix and then holding the streams open, a client can already trivially make Unbound roughly allocate double that amount. This is a remote availability issue / memory-accounting bypass in the downstream DoQ implementation that leads to denial of service for new DoQ clients. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.

CVSS Base Scores

version 3.1