What is CVE-2026-55990?
CVE-2026-55990 affects NLnet Labs Unbound versions 1.7.0 through 1.25.1, where a mismatch in the number of 'dnscrypt-provider-cert:' and 'dnscrypt-secret-key:' files leads to tail memory slots being filled with libsodium's '0xdb' fill pattern, potentially causing information leakage. This vulnerability impacts DNSCrypt configurations and may expose sensitive data. Affected systems should update Unbound to the latest version.
Azərbaycanca: CVE-2026-55990 NLnet Labs Unbound 1.7.0-dən 1.25.1-ə qədər versiyalarda, 'dnscrypt:' bölməsində 'dnscrypt-provider-cert:' faylları uyğun 'dnscrypt-secret-key:' fayllarından çox olduqda, istifadə olunmayan yaddaş sahələrinin libsodium-un '0xdb' dəyəri ilə doldurulması nəticəsində məlumat sızmasına səbəb ola bilər. Bu zəiflik DNSCrypt konfiqurasiyasına təsir edir və sistemdəki həssas məlumatların ifşasına yol aça bilər. Təsirlənmiş sistemlərdə Unbound proqramını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of NLnet Labs Unbound are affected by CVE-2026-55990?
CVE-2026-55990 affects NLnet Labs Unbound versions 1.7.0 through 1.25.1.
What is the root cause of this vulnerability?
The vulnerability occurs when the number of 'dnscrypt-provider-cert:' files exceeds the number of 'dnscrypt-secret-key:' files, causing tail memory slots to be filled with libsodium's '0xdb' fill pattern.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.