News

USN-8873-1: Two Unbound Flaws, Update to Patched Versions

Ubuntu fixes two vulnerabilities in Unbound (CVE-2026-81642, CVE-2026-82717) that allow DoS or arbitrary code execution.

UptimeMag editorial team · 6 October 2026 · 2 min read

USN-8873-1: due falle in Unbound, aggiornare alle versioni patchate

Ubuntu has published security advisory USN-8873-1, dated 6 October 2026, fixing two vulnerabilities in Unbound, the validating, recursive, caching DNS resolver used on many servers and network appliances. For anyone running their own DNS or providing resolution services to clients, this is a package to update straight away, not to put off.

The two CVEs

According to the official Ubuntu advisory, Yuqi Qiu and Xiang Li discovered that Unbound mishandled certain memory operations: an attacker could exploit the issue to cause a denial of service or execute arbitrary code (CVE-2026-81642).

Ben Morris discovered a similar issue, also related to improper memory handling, with the same potential impact: DoS or arbitrary code execution (CVE-2026-82717).

Fixed versions

Ubuntu release Package Fixed version
26.04 LTS (resolute) unbound, libunbound8, python3-unbound 1.24.2-1ubuntu2.3
24.04 LTS (noble) unbound, libunbound8, python3-unbound 1.19.2-1ubuntu3.10
22.04 LTS (jammy) unbound, libunbound8, python3-unbound 1.13.1-1ubuntu5.16
20.04 LTS (focal) unbound, libunbound8, python-unbound, python3-unbound 1.9.4-2ubuntu1.11+esm2 — requires Ubuntu Pro
18.04 LTS (bionic) unbound, libunbound2, python-unbound, python3-unbound 1.6.7-1ubuntu2.6+esm5 — requires Ubuntu Pro
16.04 LTS (xenial) unbound, libunbound2, python-unbound 1.5.8-1ubuntu1.1+esm4 — requires Ubuntu Pro with the Legacy Support add-on
14.04 LTS (trusty) unbound, libunbound2, python-unbound 1.4.22-1ubuntu4.14.04.3+esm4 — requires Ubuntu Pro with the Legacy Support add-on

For 26.04, 24.04 and 22.04 LTS, the patches are available in the standard repositories. For older releases (20.04 and earlier, now out of standard support), the fix is only available via Ubuntu Pro, the extended security maintenance (ESM) programme that covers over 25,000 packages in Main and Universe for up to ten years and is free for up to five machines.

What to do

As Ubuntu notes, in general a standard system update (apt update && apt upgrade or equivalent) will automatically apply the fixes on supported releases. On machines running 20.04 LTS or earlier without active Ubuntu Pro cover, check ESM coverage first: without a subscription, the package remains vulnerable.

References: CVE-2026-81642, CVE-2026-82717, official advisory USN-8873-1 on ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.