Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-55973] Denial of Service via malformed EDNS Report-Channel option

This high-severity Red Hat Linux advisory covers CVE-2026-55973 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.22.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-55973 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain.

When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name.

That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'.

One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon. A flaw was found in Unbound.

When the 'dns-error-reporting: yes' option is enabled, a remote attacker can send a specially crafted DNS response containing a malformed EDNS Report-Channel option from a delegated zone they control. This can lead to a stack variable overwrite, causing the Unbound daemon to terminate.

This vulnerability results in a denial of service.

Affected versions
  • 1.23.0
  • 1.25.1

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • unbound-0:1.24.2-7.el10_2.4
  • unbound-0:1.24.2-3.el9_8.4
  • rhcos-4.22.9.8.202608251819-0
  • unbound-main-1.25.2-0.1.hum1
  • RHSA-2026:55892
  • RHSA-2026:55841
  • RHSA-2026:60440
  • RHSA-2026:43588

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation

Upgrade to a fixed release: unbound-0:1.24.2-7.el10_2.4, unbound-0:1.24.2-3.el9_8.4, rhcos-4.22.9.8.202608251819-0, unbound-main-1.25.2-0.1.hum1, RHSA-2026:55892, RHSA-2026:55841. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.