CVE-2019-16866: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.

Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.

Affected products

  • Canonical Ubuntu Linux: version 19.04 only
  • Nlnetlabs Unbound: before 1.9.4 (fixed in 1.9.4)

Published 2019-10-03. Last modified 2026-10-08.