What is CVE-2026-52863?
CVE-2026-52863 affects NLnet Labs Unbound versions 1.25.0 up to and including 1.25.1. A fix enabling 'respip' and 'dns64' modules coexistence creates a shallow copy of the view name, potentially leading to memory corruption under pressure. Users should apply the latest update as soon as it becomes available.
Azərbaycanca: CVE-2026-52863 NLnet Labs Unbound proqramının 1.25.0-1.25.1 versiyalarında aşkarlanmış boşluqdur. 'respip' və 'dns64' modullarının birgə işləməsi üçün tətbiq edilən düzəliş, yaddaş korrupsiyasına səbəb ola biləcək dayaz view adı kopyası yaradır. Sistem yüksək yüklənmə altında olduqda bu problem xüsusilə təhlükəlidir.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of Unbound are affected by CVE-2026-52863?
This vulnerability affects NLnet Labs Unbound versions 1.25.0 up to and including 1.25.1.
Which modules are involved in the memory corruption issue described in CVE-2026-52863?
The issue arises from a fix enabling the coexistence of the 'respip' and 'dns64' modules, which creates a shallow copy of the view name that can lead to memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.