What is CVE-2026-40691?
CVE-2026-40691 is a buffer overflow vulnerability in Unbound 1.9.0 through 1.25.1 where DNSCrypt reply encryption over TCP fails to bound the reply length against the destination buffer. The size clamp present on the UDP path is missing on the TCP path, leading to potential overflow. Immediate update to the latest patched version is required.
Azərbaycanca: CVE-2026-40691, Unbound 1.9.0 - 1.25.1 versiyalarında TCP üzərindən DNSCrypt cavabı şifrələnərkən bufer ölçüsü yoxlanılmadığı üçün buffer overflow baş verir. UDP yolunda tətbiq olunan ölçü məhdudiyyəti TCP üçün tətbiq edilmədiyindən, böyük cavablar buferi aşır. Unbound-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which versions of Unbound are affected by CVE-2026-40691?
CVE-2026-40691 affects Unbound versions 1.9.0 through 1.25.1, where a buffer overflow occurs due to missing reply length validation during DNSCrypt encryption over TCP.
How can I mitigate the CVE-2026-40691 vulnerability?
Immediate update to the latest patched version of Unbound is required, as the size clamp present on the UDP path is missing on the TCP path, leading to a potential buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.