Medium [CVE-2026-14586] Denial of Service via assertion failure in DNS-over-QUIC environments
This medium-severity Red Hat Linux advisory covers CVE-2026-14586 affecting Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service.
When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.
This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Under heavy DNS-over-QUIC (DoQ) traffic, a timing discrepancy in Unbound’s libngtcp2 library can trigger an assertion failure.
This causes the server to crash unexpectedly, resulting in a denial of service (DoS). Moderate: This Unbound vulnerability, leading to a denial of service, is contingent on the resolver being compiled with DNS-over-QUIC (DoQ) support and having a `quic-port` configured.
The flaw manifests under high concurrency and network pressure due to a timing discrepancy in the `libngtcp2` library. Red Hat deployments not utilizing DoQ or without the `quic-port` enabled are not affected.
- 1.22.0
- 1.25.1
Official advisory · high-confidence parse· fetched 16 days ago·verify at source
- unbound-main-1.25.2-0.1.hum1
- RHSA-2026:43588
Official advisory · high-confidence parse· fetched 16 days ago·verify at source
Mitigation checklist
- Disable DNS-over-QUIC (DoQ) by removing or commenting out any quic-port directives in your unbound.conf file. Restart the unbound service for the changes to take effect and prevent potential assertion crashes.
Official advisory · high-confidence parse· fetched 16 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.