CVE-2026-1678

Source
https://cve.org/CVERecord?id=CVE-2026-1678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1678
Related
  • GHSA-536f-h63g-hj42
Published
2026-03-05T07:16:11.437Z
Modified
2026-03-14T12:58:51.690719Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

dnsunpackname() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when CONFIGDNSRESOLVER is enabled.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.3.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1678.json"