CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Other sources
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.25.2-1 - Upgrade
Upgrade
NLnet Labs Unboundto a version that resolves this vulnerability.Fixed in 1.25.2 - Configuration
If using the non-default configuration with harden-referral-path: yes, note that Unbound implicitly performs the referral-path query, so no client query is required; still upgrade Unbound to 1.25.2+ to ensure the A/AAAA TTL clamping fix for the ghost domain window applies.
Unbound harden-referral-path = yes
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42955?
The severity of CVE-2026-42955 is low, rated at 3.7.
How do I fix CVE-2026-42955?
To fix CVE-2026-42955, upgrade to a version of Unbound higher than 1.25.1.
What risk level is associated with CVE-2026-42955?
CVE-2026-42955 has a risk level of 21.
What does CVE-2026-42955 address?
CVE-2026-42955 addresses issues related to clamping the TTL of A/AAAA records to prevent 'ghost domain' delegation renewals.
What software is affected by CVE-2026-42955?
CVE-2026-42955 affects NLnet Labs Unbound versions from 1.16.2 up to and including 1.25.1.