CVE-2019-16866: High severity nlnetlabs Unbound vulnerability
Last updated 25 August 2025
Other sources
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/unboundto a version that resolves this vulnerability.Fixed in 1.9.4-1Fixed in 1.9.0-2+deb10u1 - Upgrade
Upgrade
debian/unboundto a version that resolves this vulnerability.Fixed in 1.17.1-2+deb12u4Fixed in 1.17.1-2+deb12u3Fixed in 1.22.0-2+deb13u3Fixed in 1.26.1-0+deb13u1Fixed in 1.26.1-1 - Upgrade
Upgrade
Unboundto a version that resolves this vulnerability.Fixed in 1.9.4 - Configuration
Configure Unbound so the source IP address of each query matches an access-control rule.
Unbound access-control = source IP address must match an access-control rule
Event History
Frequently Asked Questions
What is CVE-2019-16866?
CVE-2019-16866 is a vulnerability in Unbound before version 1.9.4 that allows remote attackers to trigger a crash via a crafted NOTIFY query by accessing uninitialized memory.
How does CVE-2019-16866 affect Unbound?
CVE-2019-16866 affects Unbound versions before 1.9.4.
What is the severity of CVE-2019-16866?
CVE-2019-16866 has a severity rating of 7.5 (High).
How can I fix CVE-2019-16866?
To fix CVE-2019-16866, update Unbound to version 1.9.4 or higher.
Where can I find more information about CVE-2019-16866?
More information about CVE-2019-16866 can be found at the following references: [CVE-2019-16866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16866), [NLnetlabs](https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt), [GitHub](https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog).