ALAS2UNBOUND-1.17-2026-011


Amazon Linux 2 (EOS) Security Advisory: ALAS2UNBOUND-1.17-2026-011
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
Severity: Important

Issue Overview:

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain. (CVE-2026-80225)

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability. (CVE-2026-81634)

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution. (CVE-2026-82717)

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users. (CVE-2026-85501)


Affected Packages:

unbound


Note:

This advisory is applicable to Amazon Linux 2 - Unbound-1.17 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update unbound or yum update --advisory ALAS2UNBOUND-1.17-2026-011 to update your system.

New Packages:
aarch64:
    unbound-1.17.0-2.amzn2.0.14.aarch64
    unbound-devel-1.17.0-2.amzn2.0.14.aarch64
    unbound-libs-1.17.0-2.amzn2.0.14.aarch64
    unbound-anchor-1.17.0-2.amzn2.0.14.aarch64
    unbound-utils-1.17.0-2.amzn2.0.14.aarch64
    python2-unbound-1.17.0-2.amzn2.0.14.aarch64
    python3-unbound-1.17.0-2.amzn2.0.14.aarch64
    unbound-debuginfo-1.17.0-2.amzn2.0.14.aarch64

src:
    unbound-1.17.0-2.amzn2.0.14.src

x86_64:
    unbound-1.17.0-2.amzn2.0.14.x86_64
    unbound-devel-1.17.0-2.amzn2.0.14.x86_64
    unbound-libs-1.17.0-2.amzn2.0.14.x86_64
    unbound-anchor-1.17.0-2.amzn2.0.14.x86_64
    unbound-utils-1.17.0-2.amzn2.0.14.x86_64
    python2-unbound-1.17.0-2.amzn2.0.14.x86_64
    python3-unbound-1.17.0-2.amzn2.0.14.x86_64
    unbound-debuginfo-1.17.0-2.amzn2.0.14.x86_64