Ubuntu patches two memory-handling flaws in the Unbound DNS resolver
Canonical published USN-8873-1 on 6 October, fixing two vulnerabilities in Unbound, the validating, recursive, caching DNS resolver.
The two flaws. Both are described the same way: Unbound "did not correctly handle certain memory operations", and an attacker could possibly use this to cause a denial of service or execute arbitrary code.
- CVE-2026-81642, discovered by Yuqi Qiu and Xiang Li.
- CVE-2026-82717, discovered by Ben Morris.

Who is affected. The notice covers every Ubuntu LTS release from 14.04 to 26.04. Fixed package versions include:
- 26.04 LTS:
unbound,libunbound8andpython3-unbound1.24.2-1ubuntu2.3 - 24.04 LTS: 1.19.2-1ubuntu3.10
- 22.04 LTS: 1.13.1-1ubuntu5.16
- 20.04 LTS and older: fixes through Ubuntu Pro (ESM), for example 1.9.4-2ubuntu1.11+esm2 on 20.04 and 1.6.7-1ubuntu2.6+esm5 on 18.04.
What to do. Canonical's instruction is short: a standard system update makes the necessary changes. Because Unbound is often the resolver that every other service on a host depends on, restarting it after the upgrade matters as much as installing the package — a running daemon keeps the old code until it restarts.
Unbound is maintained upstream by NLnet Labs; the Ubuntu notice gives only the CVE identifiers and the general class of the bugs, not the triggering input.