Repository navigation
CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7 #476
Copy link
Copy link
Open
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
Activity
- addedMend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
on Jul 23, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Jul 23, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 21, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 26, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 26, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 28, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Aug 28, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Sep 4, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Sep 4, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Sep 17, 2026 - changed the title
[-]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4[/+]on Sep 17, 2026 mend-bolt-for-github commented
on Sep 18, 2026 ContributorAuthorMore actions✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
- changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4[/-][+]CVE-2026-55990 (Medium) detected in src4.0.4 - autoclosed[/+]on Sep 18, 2026 mend-bolt-for-github commented
on Sep 18, 2026 ContributorAuthorMore actions✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
- changed the title
[-]CVE-2026-55990 (Medium) detected in src4.0.4 - autoclosed[/-][+]CVE-2026-55990 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Oct 7, 2026 mend-bolt-for-github commented
on Oct 7, 2026 ContributorAuthorMore actionsℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Metadata
Metadata
Assignees
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
CVE-2026-55990 - Medium Severity Vulnerability
The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....
Library home page: https://github.com/freebsd/freebsd-src.git
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/4.0, master
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').
Publish Date: 2026-07-22
URL: CVE-2026-55990
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here