Versions mentioned in the description apply to the upstream
Remediation section below for
Debian:10 relevant versions.
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
unbound to version 1.4.14-1 or higher.