Improper Resource Locking Affecting unbound package, versions [1.14.0,1.25.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-UNBOUND-16799838
  • published22 May 2026
  • disclosed20 May 2026
  • creditQifan Zhang

Introduced: 20 May 2026

CVE-2026-44608  (opens in a new tab)
CWE-413  (opens in a new tab)

How to fix?

Upgrade unbound to version 1.25.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Resource Locking in multi-threaded environments when a locking inconsistency occurs during an RPZ zone transfer reload involving rpz-nsip or rpz-nsdname triggers. An attacker can cause a system crash by exploiting a timing issue that leads to a heap use-after-free condition during the reload process.

Workaround

This vulnerability can be mitigated by avoiding the use of rpz-nsip or rpz-nsdname triggers within Response Policy Zones configured for zone transfer reloads, or by configuring the service to use local RPZ files instead of XFR for these zones.

CVSS Base Scores

version 4.0
version 3.1