Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-81642: Unbound DNS service may allow remote code execution
CVE-2026-81642 · published 17 days ago
Summary
The Unbound DNS resolver used on Debian systems can be manipulated by an attacker to run malicious code on the server. This could let an attacker take control of the machine or disrupt its operation. Apply the latest updates for Unbound from your distribution’s package manager as soon as possible.
What to do
- Update unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update rootio-unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update unbound to version 1.22.0-2+deb13u3.aikido.4.
- Update rootio-unbound to version 1.22.0-2+deb13u3.aikido.4.
- Update unbound to version 1.25.2-r2.
- Update debian unbound to version 1.26.1-0+deb13u1.
- Update debian unbound to version 1.26.1-1.
- Update unbound to version 1.25.2-r0.
- Update nlnetlabs unbound to version 1.26.1 or later.
- Update nlnet labs unbound to version 1.26.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | unbound | All versions |
| Root:Debian:12 | – | unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| Root:Debian:12 | – | rootio-unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| – | nlnetlabs | unbound |
< 1.26.1 cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* |
| – | nlnet labs | unbound | < 1.26.1 |
| Ubuntu:Pro:14.04:LTS | canonical | unbound | All versions |
| Root:Debian:13 | – | unbound |
< 1.22.0-2+deb13u3.aikido.4 Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
|
| Root:Debian:13 | – | rootio-unbound |
< 1.22.0-2+deb13u3.aikido.4 Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
|
| Alpine:v3.24 | – | unbound |
< 1.25.2-r2 Fix: upgrade to 1.25.2-r2
|
| Debian:13 | debian | unbound |
< 1.26.1-0+deb13u1 Fix: upgrade to 1.26.1-0+deb13u1
|
| Debian:14 | debian | unbound |
< 1.26.1-1 Fix: upgrade to 1.26.1-1
|
| Alpine:v3.23 | – | unbound |
< 1.25.2-r0 Fix: upgrade to 1.25.2-r0
|
Original advisory text
CVE-2026-81642 in unbound - Patched by Root
Root has patched CVE-2026-81642 in the unbound package for Root:Debian:13. Multiple fixed versions available.
References
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt Mitigation Patch Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-81642 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-81642 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-81642 Third Party Advisory
- https://nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt Third Party Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-81642 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-81642 · NVD
CVE-2026-81642 · MITRE
DEBIAN-CVE-2026-81642 · OSV
UBUNTU-CVE-2026-81642 · OSV
ALPINE-CVE-2026-81642 · OSV
CVE-2026-81642 · OSV
Track software like this
Free during beta