Dev News Daily ENDE

Ubuntu patches two memory-handling flaws in the Unbound DNS resolver

Canonical published USN-8873-1 on 6 October, fixing two vulnerabilities in Unbound, the validating, recursive, caching DNS resolver.

The two flaws. Both are described the same way: Unbound "did not correctly handle certain memory operations", and an attacker could possibly use this to cause a denial of service or execute arbitrary code.

  • CVE-2026-81642, discovered by Yuqi Qiu and Xiang Li.
  • CVE-2026-82717, discovered by Ben Morris.
Ubuntu patches two memory-handling flaws in the Unbound DNS resolver
Ubuntu patches two memory-handling flaws in the Unbound DNS resolver — Dev News Daily

Who is affected. The notice covers every Ubuntu LTS release from 14.04 to 26.04. Fixed package versions include:

  • 26.04 LTS: unbound, libunbound8 and python3-unbound 1.24.2-1ubuntu2.3
  • 24.04 LTS: 1.19.2-1ubuntu3.10
  • 22.04 LTS: 1.13.1-1ubuntu5.16
  • 20.04 LTS and older: fixes through Ubuntu Pro (ESM), for example 1.9.4-2ubuntu1.11+esm2 on 20.04 and 1.6.7-1ubuntu2.6+esm5 on 18.04.

What to do. Canonical's instruction is short: a standard system update makes the necessary changes. Because Unbound is often the resolver that every other service on a host depends on, restarting it after the upgrade matters as much as installing the package — a running daemon keeps the old code until it restarts.

Unbound is maintained upstream by NLnet Labs; the Ubuntu notice gives only the CVE identifiers and the general class of the bugs, not the triggering input.

Primary source
Ubuntu Security Notices
https://ubuntu.com/security/notices/USN-8873-1