USN-8873-1: Two Unbound Flaws, Update to Patched Versions
Ubuntu fixes two vulnerabilities in Unbound (CVE-2026-81642, CVE-2026-82717) that allow DoS or arbitrary code execution.
UptimeMag editorial team · 6 October 2026 · 2 min read

Ubuntu has published security advisory USN-8873-1, dated 6 October 2026, fixing two vulnerabilities in Unbound, the validating, recursive, caching DNS resolver used on many servers and network appliances. For anyone running their own DNS or providing resolution services to clients, this is a package to update straight away, not to put off.
The two CVEs
According to the official Ubuntu advisory, Yuqi Qiu and Xiang Li discovered that Unbound mishandled certain memory operations: an attacker could exploit the issue to cause a denial of service or execute arbitrary code (CVE-2026-81642).
Ben Morris discovered a similar issue, also related to improper memory handling, with the same potential impact: DoS or arbitrary code execution (CVE-2026-82717).
Fixed versions
| Ubuntu release | Package | Fixed version |
|---|---|---|
| 26.04 LTS (resolute) | unbound, libunbound8, python3-unbound | 1.24.2-1ubuntu2.3 |
| 24.04 LTS (noble) | unbound, libunbound8, python3-unbound | 1.19.2-1ubuntu3.10 |
| 22.04 LTS (jammy) | unbound, libunbound8, python3-unbound | 1.13.1-1ubuntu5.16 |
| 20.04 LTS (focal) | unbound, libunbound8, python-unbound, python3-unbound | 1.9.4-2ubuntu1.11+esm2 — requires Ubuntu Pro |
| 18.04 LTS (bionic) | unbound, libunbound2, python-unbound, python3-unbound | 1.6.7-1ubuntu2.6+esm5 — requires Ubuntu Pro |
| 16.04 LTS (xenial) | unbound, libunbound2, python-unbound | 1.5.8-1ubuntu1.1+esm4 — requires Ubuntu Pro with the Legacy Support add-on |
| 14.04 LTS (trusty) | unbound, libunbound2, python-unbound | 1.4.22-1ubuntu4.14.04.3+esm4 — requires Ubuntu Pro with the Legacy Support add-on |
For 26.04, 24.04 and 22.04 LTS, the patches are available in the standard repositories. For older releases (20.04 and earlier, now out of standard support), the fix is only available via Ubuntu Pro, the extended security maintenance (ESM) programme that covers over 25,000 packages in Main and Universe for up to ten years and is free for up to five machines.
What to do
As Ubuntu notes, in general a standard system update (apt update && apt upgrade or equivalent) will automatically apply the fixes on supported releases. On machines running 20.04 LTS or earlier without active Ubuntu Pro cover, check ESM coverage first: without a subscription, the package remains vulnerable.
References: CVE-2026-81642, CVE-2026-82717, official advisory USN-8873-1 on ubuntu.com/security/notices.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.