CVE Vulnerabilities

CVE-2026-55990

Use of Uninitialized Variable

Published: Jul 22, 2026 | Modified: Jul 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the dnscrypt: clause lists more dnscrypt-provider-cert: files than there are matching dnscrypt-secret-key: files, Unbound fills only the matched prefix and leaves the tail slots at the 0xdb fill that libsodiums allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with 0xdb bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are 0xdb to dnscrypt-port will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support (–enable-dnscrypt).

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

NameVendorStart VersionEnd Version
UnboundUbuntuupstream*

Potential Mitigations

References