Two Resolvers, Two Advisories: The Unbound DNSKEY Overflow (CVE-2026-81642) and the BIND SIG(0) Crash
On consecutive days in September 2026, the maintainers of two independent DNS resolver implementations published high-severity advisories. NLnet Labs released Unbound 1.26.1 on 17 September, and ISC published BIND 9.20.29 and 9.21.26 on 16 September. The overlap points at something larger than either release. The resolution layer is being re-audited, and the bugs found there sit in front of nearly every network.
The Unbound validator overflow
CVE-2026-81642 carries a CVSS base score of 9.1 and affects the DNSSEC validator. The trigger is a DNSKEY record whose owner name is a compression pointer aimed at that record's own data. The validator follows the pointer, performs an invalid self-referential read, and overflows heap memory. No authentication and no user interaction are involved. An attacker only needs to control a malicious zone and persuade the resolver to query it, which is what a resolver is built to do. The advisory notes the possibility of remote code execution.
The affected range covers 1.26.0 and everything earlier, including the 1.25.2 security release from July and the 1.26.0 feature release from August. Unbound 1.26.1 is the complete fix. The same release addresses eight further CVEs for nine in total, among them CVE-2026-82717, a high-severity heap corruption in CNAME synthesis reported by a researcher working with Anthropic that the maintainers say may permit remote code execution on some platforms.
NLnet Labs states there is no known exploitation in the wild, and the initial CISA Known Exploited Vulnerabilities entry records no exploitation. Standalone source patches for 1.26.0 are available that address CVE-2026-81642 and CVE-2026-82717 for operators who cannot move to the new release immediately.
The BIND denial of service
The BIND release fixes fourteen security defects. One of them affects any server that answers DNS over HTTPS. An unauthenticated sender transmits a request carrying an invalid SIG(0) signature and disconnects before named finishes validating the signature. A single request terminates the named process. ISC reports that none of the fourteen were known to be exploited at publication.
Why the timing is the story
DNS resolvers handle traffic from networks that have no prior relationship with them, so every parsing decision in the validation path is reachable by an anonymous sender. That is hard to design around, and it explains why both projects found multiple issues in one review cycle. The practical takeaway for operators is procedural. Unbound 1.26.1 and BIND 9.20.29 or 9.21.26 are the versions that close the reported defects, and an asset inventory that lists resolver versions by package rather than by running process will mislead the response.
References
- NLnet Labs advisory for Unbound 1.26.1, covering CVE-2026-81642 and CVE-2026-82717, 17 September 2026.
- ISC advisory for BIND 9.20.29 and 9.21.26, 16 September 2026.
Top comments (0)