Skip to content

CVE-2026-56416 (Medium) detected in src4.0.4, src4.0.4 #471

Description

@mend-bolt-for-github

CVE-2026-56416 - Medium Severity Vulnerability

Vulnerable Libraries - src4.0.4, src4.0.4

src4.0.4

Library home page: https://github.com/MidnightBSD/src.git

Vulnerable Source Files (2)

/contrib/unbound/util/data/msgparse.c
/contrib/unbound/validator/val_sigcrypt.c

src4.0.4

Library home page: https://github.com/MidnightBSD/src.git

Vulnerable Source Files (2)

/contrib/unbound/util/data/msgparse.c
/contrib/unbound/validator/val_sigcrypt.c

Found in base branches: stable/4.0, master

Vulnerability Details

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed authoritative server can deliver a record with an absent second domain name (e.g. SOA record) and cause 'query_dname_tolower()' to walk label-by-label through stale bytes in the per-worker 'env->scratch_buffer', past the end of that heap allocation if 'msg-buffer-size' has been lowered from the default. This leads to heap buffer overflow and on a release build the outcome relies heavily on the contents of the buffer tail and the adjacent heap chunk.

Publish Date: 2026-07-22

URL: CVE-2026-56416

CVSS 3 Score Details (4.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-22

Fix Resolution: https://github.com/NLnetLabs/unbound.git - release-1.25.2


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions