{"id":"AZL-92943","summary":"CVE-2026-44621 affecting package unbound for versions less than 1.25.2-1","details":"With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush.","modified":"2026-08-28T17:47:53.538008706Z","published":"2026-07-22T14:17:18Z","upstream":["CVE-2026-44621"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44621"}],"affected":[{"package":{"name":"unbound","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/unbound"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92943.json"}}],"schema_version":"1.9.0"}