Echo: unbound: security update to 1.25.1-1

high Tenable Self-Hosted Container Security Plugin ID 461589

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC
validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply
messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section
rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease
the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator
later dereferences this uninitialized pointer, causing an immediate process crash. An adversary
controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain
with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue
records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write
offsets. (CVE-2026-42959)

Solution

Update the unbound library and its related packages to version 1.25.1-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-42959

Plugin Details

Severity: High

ID: 461589

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-42959

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/21/2026

Vulnerability Publication Date: 5/20/2026

Reference Information

CVE: CVE-2026-42959