📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 28m Global general Technology / Consumer Protection MEDIUM 39m Global vulnerability Information Technology and Security CRITICAL 47m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 28m Global general Technology / Consumer Protection MEDIUM 39m Global vulnerability Information Technology and Security CRITICAL 47m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 28m Global general Technology / Consumer Protection MEDIUM 39m Global vulnerability Information Technology and Security CRITICAL 47m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-44608

Medium
CWE-413 — Weakness Type
Published: May 20, 2026  ·  Modified: May 23, 2026  ·  Source: NVD
CVSS v3
5.9
🔗 NVD Official
📄 Description (English)

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.

🤖 AI Executive Summary

NLnet Labs Unbound versions 1.14.0 through 1.25.0 contain a locking inconsistency vulnerability in multi-threaded configurations with RPZ XFR reloads that can cause heap use-after-free and crash. The vulnerability requires specific conditions: multi-threaded operation, RPZ zones with 'rpz-nsip'/'rpz-nsdname' triggers, and concurrent XFR operations, which is patched in version 1.25.1.

📄 Description (Arabic)

تؤثر هذه الثغرة على خوادم DNS Unbound المستخدمة في البيئات متعددة الخيوط مع تفعيل Response Policy Zones (RPZ). عندما يحدث تحديث XFR لمنطقة RPZ في نفس الوقت الذي تحاول فيه خيط آخر قراءة البيانات، قد لا يتم الاحتفاظ بالقفل بشكل صحيح مما يؤدي إلى استخدام الذاكرة بعد تحريرها. هذا يمكن أن يسبب تعطل الخدمة وانقطاع الخدمة.

🤖 ملخص تنفيذي (AI)

إصدارات NLnet Labs Unbound من 1.14.0 إلى 1.25.0 تحتوي على ثغرة عدم اتساق القفل في التكوينات متعددة الخيوط مع إعادة تحميل RPZ XFR التي قد تسبب استخدام الذاكرة بعد التحرير والتعطل. تتطلب الثغرة شروطاً محددة: التشغيل متعدد الخيوط وعناصر RPZ مع مشغلات 'rpz-nsip'/'rpz-nsdname' والعمليات المتزامنة، وهو مصحح في الإصدار 1.25.1.

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 13:06
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
telecom government banking energy
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Upgrade NLnet Labs Unbound to version 1.25.1 or later immediately. For organizations unable to upgrade immediately, disable multi-threaded operation or RPZ zones with 'rpz-nsip'/'rpz-nsdname' triggers as temporary mitigations. Monitor DNS resolver logs for unexpected crashes or service interruptions.
🔧 خطوات المعالجة (العربية)
قم بترقية NLnet Labs Unbound إلى الإصدار 1.25.1 أو أحدث على الفور. للمنظمات غير القادرة على الترقية فوراً، قم بتعطيل التشغيل متعدد الخيوط أو عناصر RPZ مع مشغلات 'rpz-nsip'/'rpz-nsdname' كتدابير مؤقتة. راقب سجلات محلل DNS للتعطل غير المتوقع أو انقطاع الخدمة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.13.1.1 A.12.6.1
🔵 SAMA CSF
ID.BE-1 PR.IP-1 PR.MA-2
🟡 ISO 27001:2022
12.6.1 14.2.1
📦 Affected Products / CPE 1 entries
nlnetlabs:unbound
📊 CVSS Score
5.9
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score5.9
CWECWE-413
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-05-20
Source Feed nvd
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-413
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.