CVE-2026-32792: Packet of death with DNSCrypt

Published May 20, 2026
·
Updated

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.

Affected Software

3 affected componentsFixes available
Nlnet Labs Unbound>=1.6.2<=1.25.0
nlnetlabs Unbound>=1.6.2<1.25.1
Microsoft azl3 unbound 1.19.1-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.25.1
  2. Configuration

    If you cannot immediately upgrade to Unbound 1.25.1, rebuild Unbound without DNSCrypt support (do not compile with '--enable-dnscrypt') to avoid the vulnerable DNSCrypt packet reading procedure.

    Unbound DNSCrypt support (compiled with --enable-dnscrypt) --enable-dnscrypt = disabled

Event History

May 20, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
May 21, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-32792?

CVE-2026-32792 is classified as a denial of service vulnerability that can potentially lead to service disruption.

2

How do I fix CVE-2026-32792?

To address CVE-2026-32792, it is recommended to update NLnet Labs Unbound to a version beyond 1.25.0.

3

What software is affected by CVE-2026-32792?

CVE-2026-32792 affects NLnet Labs Unbound versions from 1.6.2 up to and including 1.25.0 when compiled with DNSCrypt support.

4

What type of vulnerability is CVE-2026-32792?

CVE-2026-32792 is a denial of service vulnerability that occurs due to a bad DNSCrypt query leading to a potential heap overflow.

5

Is CVE-2026-32792 exploitable remotely?

Yes, CVE-2026-32792 can be exploited remotely through malicious DNSCrypt queries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203