Urgent.News

What's breaking now, across thousands of outlets.

Tech

I Traced Unbound's DNSSEC Heap Overflow: 4 Checks to Run

[ attacker's zone ] ──► ┌────────────────────────────┐ │ Unbound (recursive, DNSSEC)│ │ CVE-2026-81642 CWE-122 │ │ DNSKEY -> digest buffer │ └────────────────────────────┘ A compression pointer inside a DNSSEC key record can overflow a heap buffer in the most security-conscious component of your resolver stack, and the vendor's own advisory says remote code execution is possible through attacker…

CVE-2026-81642 and CVE-2026-86003 are two critical vulnerabilities affecting Unbound and CoreDNS respectively. The Unbound vulnerability is a heap overflow in the DNSSEC validator caused by a compression pointer within a DNSKEY record that points back to itself. This allows an attacker to cause remote code execution through attacker-controlled data.

Similarly, the CoreDNS vulnerability arises from unauthenticated DNS UPDATEs being accepted over encrypted transports, allowing an attacker to exploit the trusted middleman role and potentially take over names. Both issues affect all releases up to 1.26.0, with Unbound patched in 1.26.1 and CoreDNS in 1.14.7. The primary risk comes from users unknowingly querying malicious domains through compromised links, as no public exploit has been discovered.

To mitigate these threats, it is crucial to verify the exact versions of Unbound and CoreDNS running on resolver hosts, conduct a comprehensive inventory of resolvers within the network, and promptly apply the respective patches.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Add an FAQ bot and appointment booking to any website with 3 API calls

Most small-business sites need the same two things: answer the five questions everyone asks ("what are your hours?", "how much is…?") and let people book.

  • Add FAQ bot and booking to website via 3 API calls
  • Use CallChatSyn API with free first 1,000 businesses
  • Implement widget with 30 lines JavaScript code

A threshold is a policy, not a number

A threshold is a policy, not a number Somewhere in a payments codebase there is a line that says: approve automatically when confidence is above 0.8. Nobody remembers the afternoon it was written.

  • The 0.8 confidence threshold in payments codebases determines automatic refunds or human review.
  • The origin of the 0.8 value is unclear, stemming from various unrelated sources.
  • Setting the threshold improperly can cause irreversible damage or hidden costs for the business.

The Task Ahead of STN as National Telecoms Licence Operator in Nigeria

After 28 years of operating skeletal telecoms services under the umbrella, Swift Telephone Network (STN) has become a full-fledged telecoms operator after being granted the Universal Access Service…

  • Swift Telephone Network (STN) secured UASL from NCC, enabling nationwide telecom services.
  • Post-2017 revival, Oluwole Adetuyi focused on regulatory compliance before receiving UASL in 2022.

Rust's derive often implies inline

  • Rust #[derive] often adds #[inline] to core traits like Debug
  • Inlining Debug implementations can significantly increase binary size
  • Preventing inlining can reduce binary size by 160KB in some cases

More from Sunday 4 October →