Echo: unbound: security update to 1.25.1-1

high Tenable Cloud Security Plugin ID 460586

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when
compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's
DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the
vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00'
bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than
necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory
layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low,
since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow
does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with
a fix to bound reading in the given buffer space. (CVE-2026-32792)

Solution

Update the unbound library and its related packages to version 1.25.1-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-32792

Plugin Details

Severity: High

ID: 460586

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-32792

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 4.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/21/2026

Vulnerability Publication Date: 5/20/2026

Reference Information

CVE: CVE-2026-32792