Data Element containing Pointer Item without Proper Copy Control Element Affecting unbound package, versions <0:1.25.2-0.1.hum1


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-UNBOUND-18475994
  • published31 Jul 2026
  • disclosed22 Jul 2026

Introduced: 22 Jul 2026

NewCVE-2026-52863  (opens in a new tab)
CWE-1098  (opens in a new tab)

How to fix?

Upgrade RHEL:10 unbound to version 0:1.25.2-0.1.hum1 or higher.
This issue was patched in RHSA-2026:43588.

NVD Description

Note: Versions mentioned in the description apply only to the upstream unbound package and not the unbound package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz' modules, together with a module that can attach subqueries (respip CNAME redirection, dns64, subnetcache) and a configured 'access-control-view' while Unbound is under pressure so that joslte logic kicks in and starts dropping slow queries. The subquery is getting a shallow copy of the view name and if the super query which owns the view name is jostled out, memory corruption can occur. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. Debug memory builds (e.g., ASAN) that catch the free terminate the server.

CVSS Base Scores

version 3.1