Skip to content
VulniPulse
Advisory severityMedium5.9Red Hat Linux

Medium [CVE-2026-14586] Denial of Service via assertion failure in DNS-over-QUIC environments

This medium-severity Red Hat Linux advisory covers CVE-2026-14586 affecting Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-14586 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service.

When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.

This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Under heavy DNS-over-QUIC (DoQ) traffic, a timing discrepancy in Unbound’s libngtcp2 library can trigger an assertion failure.

This causes the server to crash unexpectedly, resulting in a denial of service (DoS). Moderate: This Unbound vulnerability, leading to a denial of service, is contingent on the resolver being compiled with DNS-over-QUIC (DoQ) support and having a `quic-port` configured.

The flaw manifests under high concurrency and network pressure due to a timing discrepancy in the `libngtcp2` library. Red Hat deployments not utilizing DoQ or without the `quic-port` enabled are not affected.

Affected versions
  • 1.22.0
  • 1.25.1

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Fixed versions
  • unbound-main-1.25.2-0.1.hum1
  • RHSA-2026:43588

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Disable DNS-over-QUIC (DoQ) by removing or commenting out any quic-port directives in your unbound.conf file. Restart the unbound service for the changes to take effect and prevent potential assertion crashes.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.