Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.7

CVE-2026-42960: Unbound DNS resolver can be tricked into cache poisoning

CVE-2026-42960 · published 4 months ago
Summary

Versions of the Unbound DNS service up to 1.25.0 may store false DNS information if an attacker sends specially crafted responses. This could cause users to be directed to malicious sites or intercept communications. Upgrade to version 1.25.1 or later, which blocks the unwanted data, to protect against this risk.

What to do
  • Update canonical unbound to version 1.22.0-2ubuntu2.3.
  • Update canonical unbound to version 1.24.2-1ubuntu2.1.
  • Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.1.
  • Update debian unbound to version 1.25.1-1.
  • Update canonical unbound to version 1.4.22-1ubuntu4.14.04.3+esm3.
  • Update canonical unbound to version 1.5.8-1ubuntu1.1+esm3.
  • Update canonical unbound to version 1.6.7-1ubuntu2.6+esm4.
  • Update canonical unbound to version 1.9.4-2ubuntu1.11+esm1.
  • Update canonical unbound to version 1.13.1-1ubuntu5.15.
  • Update canonical unbound to version 1.19.2-1ubuntu3.8.
  • Update debian rootio-unbound to version 1.17.1-2+deb12u3.root.io.1.
  • Update debian unbound to version 1.17.1-2+deb12u4.aikido.2.
  • Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.2.
  • Update debian unbound to version 1.13.1-1+deb11u7.aikido.1.
  • Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.6.
  • Update debian unbound to version 1.13.1-1+deb11u7.aikido.3.
  • Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.3.
  • Update debian unbound to version 1.13.1-1+deb11u7.aikido.6.
  • Update debian unbound to version 1.17.1-2+deb12u4.aikido.3.
  • Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.3.
  • Update debian unbound to version 1.17.1-2+deb12u4.aikido.4.
  • Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.4.
  • Update unbound to version 1.17.1-2+deb12u4.aikido.5.
  • Update rootio-unbound to version 1.17.1-2+deb12u4.aikido.5.
  • Update unbound to version 1.25.2-r0.
  • Update unbound to version 1.25.1-r0.
  • Update nlnetlabs unbound to version 1.25.1 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:25.10 canonical unbound < 1.22.0-2ubuntu2.3
Fix: upgrade to 1.22.0-2ubuntu2.3
Ubuntu:26.04:LTS canonical unbound < 1.24.2-1ubuntu2.1
Fix: upgrade to 1.24.2-1ubuntu2.1
Root:Debian:11 debian rootio-unbound < 1.13.1-1+deb11u7.aikido.1
< 1.13.1-1+deb11u7.aikido.6
< 1.13.1-1+deb11u7.aikido.3
Fix: upgrade to 1.13.1-1+deb11u7.aikido.1
– nlnetlabs unbound < 1.25.1
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*
Debian:11 debian unbound All versions
Debian:12 debian unbound All versions
Debian:13 debian unbound All versions
Debian:14 debian unbound < 1.25.1-1
Fix: upgrade to 1.25.1-1
Ubuntu:Pro:14.04:LTS canonical unbound < 1.4.22-1ubuntu4.14.04.3+esm3
Fix: upgrade to 1.4.22-1ubuntu4.14.04.3+esm3
Ubuntu:Pro:16.04:LTS canonical unbound < 1.5.8-1ubuntu1.1+esm3
Fix: upgrade to 1.5.8-1ubuntu1.1+esm3
Ubuntu:Pro:18.04:LTS canonical unbound < 1.6.7-1ubuntu2.6+esm4
Fix: upgrade to 1.6.7-1ubuntu2.6+esm4
Ubuntu:Pro:20.04:LTS canonical unbound < 1.9.4-2ubuntu1.11+esm1
Fix: upgrade to 1.9.4-2ubuntu1.11+esm1
Ubuntu:22.04:LTS canonical unbound < 1.13.1-1ubuntu5.15
Fix: upgrade to 1.13.1-1ubuntu5.15
Ubuntu:24.04:LTS canonical unbound < 1.19.2-1ubuntu3.8
Fix: upgrade to 1.19.2-1ubuntu3.8
Root:Debian:12 debian rootio-unbound < 1.17.1-2+deb12u3.root.io.1
< 1.17.1-2+deb12u4.aikido.2
< 1.17.1-2+deb12u4.aikido.3
< 1.17.1-2+deb12u4.aikido.4
Fix: upgrade to 1.17.1-2+deb12u3.root.io.1
Root:Debian:12 debian unbound < 1.17.1-2+deb12u4.aikido.2
< 1.17.1-2+deb12u4.aikido.3
< 1.17.1-2+deb12u4.aikido.4
Fix: upgrade to 1.17.1-2+deb12u4.aikido.2
Root:Debian:11 debian unbound < 1.13.1-1+deb11u7.aikido.1
< 1.13.1-1+deb11u7.aikido.3
< 1.13.1-1+deb11u7.aikido.6
Fix: upgrade to 1.13.1-1+deb11u7.aikido.1
Root:Debian:12 – unbound < 1.17.1-2+deb12u4.aikido.5
Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
Root:Debian:12 – rootio-unbound < 1.17.1-2+deb12u4.aikido.5
Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
Alpine:v3.22 – unbound < 1.25.2-r0
Fix: upgrade to 1.25.2-r0
Alpine:v3.24 – unbound < 1.25.1-r0
Fix: upgrade to 1.25.1-r0
Original advisory text
CVE-2026-42960 in unbound - Patched by Root
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.
Severity
5.7 Medium
CVSS 4.0: 5.7 (NVD)
CVSS 4.0: 7.8 (OSV)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data
Timeline
Published20 May 2026
Updated25 Sep 2026
First seen20 May 2026
Track software like this
Free during beta