-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Sep 2026 11:55:59 +0300 Source: unbound Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym Architecture: amd64 Version: 1.26.1-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Michael Tokarev Description: libunbound-dev - static library, header files, and docs for libunbound libunbound8 - library implementing DNS resolution and validation python3-unbound - library implementing DNS resolution and validation (Python3 bindi unbound - validating, recursive, caching DNS resolver unbound-anchor - utility to securely fetch the root DNS trust anchor unbound-host - reimplementation of the 'host' command Closes: 1096189 1142539 Changes: unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium . * New upstream release fixing numerous security and other issues and contains some enhancements. . Traditionally in Debian, bugs in stable versions are fixed by providing a back-port of a fix from later upstream version to the version in Debian stable. With unbound, fixes in subsequent versions can not be applied directly to the version in Debian stable, as there were multiple other code changes in these areas. Many of these changes fixes other issues (security or not). Some changes are in areas with complex logic, hence requires creat care when back-porting to older releases. And the result of such back-porting becomes unique and rather unpredictable. So instead of trying to provide fixes for older version in Debian stable, we decided to provide current upstream version of unbound, - the same as currently available in Debian Sid. The packaging is made very similar too. . Recent security fixes: . o CVE-2026-81642 - severity: CRITICAL Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY o CVE-2026-81634 - severity: HIGH Possible heap buffer overflow during DNSSEC canonicalization o CVE-2026-82717 - severity: HIGH CNAME synthesis could lead to heap corruption o CVE-2026-77955 - severity: MEDIUM Possible ZONEMD verification bypass window o CVE-2026-78227 - severity: MEDIUM Use-after-free in DoQ stream output buffer on reset re-transmission o CVE-2026-80225 - severity: MEDIUM Possible degradation of service from continuous queries on the same TCP/DoT connection o CVE-2026-82720 - severity: MEDIUM Use-after-free in DoH stream cleanup code path o CVE-2026-85501 - severity: MEDIUM Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC o CVE-2026-77860 - severity: LOW 'serve-expired' can bypass Unbound 'wait-limit' o CVE-2026-32665 - severity: HIGH Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass o CVE-2026-40691 - severity: HIGH Packet of death for DNSCrypt over TCP o CVE-2026-44690 - severity: HIGH Cross-zone wildcard cache poisoning via RRSIG.labels manipulation o CVE-2026-55973 - severity: HIGH 'dns-error-reporting: yes' leads to stack buffer overflow o CVE-2026-14586 - severity: MEDIUM Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments o CVE-2026-44621 - severity: MEDIUM Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated o CVE-2026-50045 - severity: MEDIUM 'max-global-quota' reset by DNSSEC validation restarts o CVE-2026-50046 - severity: MEDIUM Possible heap use-after-free in an error path when a DoT forwarded query is jostled out o CVE-2026-50243 - severity: MEDIUM response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL o CVE-2026-50248 - severity: MEDIUM BOGUS configured primary hostname accepted for XFR in auth/rpz zones o CVE-2026-50251 - severity: MEDIUM Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush o CVE-2026-50252 - severity: MEDIUM Possible cache poisoning attack by mapping source port population per thread o CVE-2026-52863 - severity: MEDIUM Memory corruption could lead to crash and denial of service o CVE-2026-55717 - severity: MEDIUM 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash o CVE-2026-55990 - severity: MEDIUM Packet of death for a DNSCrypt misconfigured Unbound o CVE-2026-55991 - severity: MEDIUM Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 o CVE-2026-56416 - severity: MEDIUM Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name o CVE-2026-56444 - severity: MEDIUM Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration o CVE-2026-41637 - severity: LOW Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries o CVE-2026-42955 - severity: LOW Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records o CVE-2026-44687 - severity: LOW Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN o CVE-2026-46582 - severity: LOW A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path o CVE-2026-54478 - severity: LOW DNS Cookie bypass when combined with proxy-protocol use o CVE-2026-55708 - severity: LOW Privacy/configuration issue when adding local data in views through 'unbound-control' . Other notable user-visible changes and fixes. For complete list, please see /usr/share/doc/unbound/changelog.gz . o ICANN Bundle Update: Refreshed icannbundle.pem certificates in unbound-anchor to include public keys valid for 2009–2029 and 2025–2045 o Transfer Limits: Added max-transfer-size and max-transfer-time directives to limit authorization zone (auth-zone) and RPZ transfer sizes and times to harden against unbounded transfers. o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA queries, plus block_a_wdata and block_aaaa_wdata to support custom local data fallback. o Management Improvements: Overloaded local_data_remove to allow the removal of precise records. o Fix for the Jiggle Attack. The server is fixed to answer with errors for error cases, and does not stay silent. In addition, the error replies do not contain parts of the incoming query. This is more conformant, stops reflection and stops it as a covert channel. o Fix EDNS extended RCODE reflection. This fixes that the server does not echo extended rcode values after class chaos queries. o Fix for iterator RCODE handling of YXDOMAIN. This fixes that the server only accepts YXDOMAIN answers that contain a DNAME record. This stops bad answers, and checks that the authoritative server gives correct replies. o Fix for missing bounds check for decompressing dnames for downloaded authority zones. This fixes that the server could end up with malformed zone content after receiving truncated packet contents from an AXFR. In addition, the domain names in the SOA rdata are checked before the authority code picks up the zone serial. o Fix that upstream TLS connections are not reused as TLS connections for a different name, at the same IP. This checks that the tls name is correct when reusing the upstream connections. o Fix that signatures are not allowed with revoked dnskeys. o Fix that a DNAME with an unsigned CNAME is checked for the correct match. This stops that for certain zone configurations an unchecked unsigned CNAME could get secure status. o Fix handling of wildcard CNAMEs in the chain of trust. An improper wildcard in the chain of trust would send the retries to the wrong upstream. Also it could label the step in the chain of trust as secure, when it was not. o Introduce new 'tls-protocols' configuration option that specifies which of the supported TLS protocols will be used. o Fix RFC7766 compliance when client sends EOF over TCP. It stops pending replies and closes. o Fix to shorten RRSIG count in scrubber, this protects against an overly large number of RRSIGs. It can be configured with `iter-scrub-rrsig: 8`, it has default 8. o Fix for EDNS client subnet so that it does not store SERVFAIL in the global cache after a failed lookup, such as timeouts. A failure entry is stored in the subnet cache, for the query name, for a couple of seconds. Queries can continue to use the subnet cache during that time. o Fix to allow the control-interface config to use ip@port notation. o Fix to check for invalid http content length and chunk size, and to check the RR rdata field lengths when decompressing and inserting RRs from an authority zone transfer. This stops large memory use and heap buffer-overflow read errors. o Fix to ignore out-of-zone DNAME records for CNAME synthesis. Fix so that a reload checks if the files have changed, and if so, reload the contexts. Also for DoH, DoQ and outgoing DoT. o Apply cache TTL policy to DNAME and synthesized CNAME on wire path. o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound. o Allow synthesized DNAME TTL=0 to be served from cache within grace period. The responses are served from cache within a 1-second grace period. Reduces recursion when authoritative servers return DNAME with TTL=0 (RFC 2308). Response still returns TTL=0 to clients. o On Linux systems log the system-wide unique thread ID instead of Unbound's internal thread counter. o Introduce the 'log-thread-id' configuration option to manage logging the system-wide Linux thread ID for easier debugging with system tools. o Mesh reply counters. This adds statistics num.queries.replyaddr_limit and requestlist.current.replies. o Add extra statistic to track the number of signature validation operations. Adds 'num.valops' to extended statistics. o Fix for cname chain length with qtype ANY and qname minimisation. o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where the UDP socket send buffers are exhausted waiting for ARP/NDP resolution. o Increase default to `num-queries-per-thread: 2048`, when unbound is compiled with libevent. It makes saturation of the task queue more resource intensive and less practical. o DNS Error Reporting (RFC 9567). Introduces new configuration option 'dns-error-reporting' and new statistics for 'num.dns_error_reports'. o Redis read-only replica support. Introduces new 'redis-replica-*' options for the Redis cache backend. o Exempt loopback addresses from wait-limit. o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse to allow two arguments. o Fast Reload. The unbound-control fast_reload is added. It reads changed config in a thread, then only briefly pauses the service threads, that keep running. DNS service is only interrupted briefly. o Make the default value of module-config "validator iterator" regardless of compilation options. --enable-subnet would implicitly change the value to enable the subnetcache module by default in the past. o Add unbound members group access to control key. o Add resolver.arpa and service.arpa to the default locally served zones. o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake. o Serve expired cache update fixes. Fixes a regression bug with serve-expired that appeared in 1.22.0 and would not allow the iterator to update the cache with not-yet-validated entries resulting in increased outgoing traffic. Closes: #1142539 o The default value of serve-expired-ttl is set to 86400 (1 day) as suggested by RFC8767. o Increase the default of max-global-quota to 200 from 128 after operational feedback. Still keeping the possible amplification factor (CAMP related issues) in the hundreds. o Fix for the serve expired DNSSEC information fix, it would not allow current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses. o Statistics for discard-timeout and wait-limit. . * Other packaging changes: - d/rules,d/libunbound-dev.install: drop static library and deps (Closes: #1096189) - unbound-helper: do not update resolvconf if it is systemd-resolved - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd - d/upstream/signing-key.asc: update with the new upstream key - d/unbound.conf.d/remote-control.conf: fix typo Checksums-Sha1: a1a39026315f2d89a2cfa2c8e7bebfb49ed7ea81 213572 libunbound-dev_1.26.1-0+deb13u1_amd64.deb 13589855fdd20471042388089302769ec7c61bce 1397724 libunbound8-dbgsym_1.26.1-0+deb13u1_amd64.deb fffa33bbd0a61f827ee9179d5cba212a2c47a799 643372 libunbound8_1.26.1-0+deb13u1_amd64.deb 939ba3ee839f198e3e19cf3ac1fff8b91255a8fd 171412 python3-unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb 829493c54b66e9facc602df79e51e8ca3b962f94 246996 python3-unbound_1.26.1-0+deb13u1_amd64.deb 348beb7c08b07744c8d46ef1ffe05f19d525867f 59484 unbound-anchor-dbgsym_1.26.1-0+deb13u1_amd64.deb 8a428e33665e9fe1d599a14ec7a8d422f1e91153 222264 unbound-anchor_1.26.1-0+deb13u1_amd64.deb 576a6eaae37bf4e69a93a7cd534bd885c0a32031 5770944 unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb ae789bdef16602069a57a605fc90a80838a4ed0d 132972 unbound-host-dbgsym_1.26.1-0+deb13u1_amd64.deb 4715c7ff0f594b336d7d7beb25f4bbf185845a10 244076 unbound-host_1.26.1-0+deb13u1_amd64.deb 14576090999bbbefb2daac393116f4ea651fcba2 10600 unbound_1.26.1-0+deb13u1_amd64-buildd.buildinfo bfefca151a2d1fde006fae640459b63ad04768ec 1127212 unbound_1.26.1-0+deb13u1_amd64.deb Checksums-Sha256: e909714ea6d39833cf42e8e48f3dbe68a42147d8853850e7848769d7fd5a3d12 213572 libunbound-dev_1.26.1-0+deb13u1_amd64.deb ab02988601b8061385e54b1b75eba9f573a02560bbe1d614bc6b2b841c7282c4 1397724 libunbound8-dbgsym_1.26.1-0+deb13u1_amd64.deb 2331c4c305f68aab91dbe16245bd76c0e0edc532353b3ce52accad71d24dfbb3 643372 libunbound8_1.26.1-0+deb13u1_amd64.deb af0f10cae8059de5c7d6fc38afa6a25229b23f55412c02cf99def80f39b45367 171412 python3-unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb a14b7620cd3969e2ca3ab38583de73b3ec1955158e0956f36cf896abaa505736 246996 python3-unbound_1.26.1-0+deb13u1_amd64.deb 088bde574e22edc19a036e4e5d9d34f106c367c88dd431fcc256d0f7c367d371 59484 unbound-anchor-dbgsym_1.26.1-0+deb13u1_amd64.deb b1ace017fec8a346bba1fa587c9bb8ec076e69ce7aa67852a8a05be4dba7b3cb 222264 unbound-anchor_1.26.1-0+deb13u1_amd64.deb 4f985870d9f63286ce689b5cf131cb15a6f3b76b19920f199a7e0fca898ccbec 5770944 unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb a41d3beb87a0912e7912b54bde547327fc79ccad23c96fdfe868ce660150a33f 132972 unbound-host-dbgsym_1.26.1-0+deb13u1_amd64.deb 7bec6d16731e3684503d00475713169d3bb7c1c71db92fa2887d73dfd9f71ae9 244076 unbound-host_1.26.1-0+deb13u1_amd64.deb 64d338cc5a2ee90b2a14d5c4bb655f114bb8434ba4afaef3b4fac9e8cc8b4f3f 10600 unbound_1.26.1-0+deb13u1_amd64-buildd.buildinfo 61cc8b5954a4c39db779514ba2e60a6b8bdaa5a60b1a938cde15f1bb25078886 1127212 unbound_1.26.1-0+deb13u1_amd64.deb Files: 540714b64007b4f1c3f4d87fc5fa5b9a 213572 libdevel optional libunbound-dev_1.26.1-0+deb13u1_amd64.deb 72cee3df47804bf9c5f3304e38cebf43 1397724 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_amd64.deb 9c6ddd124f6ef1123acf2a764a95f754 643372 libs optional libunbound8_1.26.1-0+deb13u1_amd64.deb e479bdf7aa9bae7547b0ce8888771682 171412 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb ef843966c236b5991d249f068ac8a0cc 246996 python optional python3-unbound_1.26.1-0+deb13u1_amd64.deb 13955a2aa4538973c79ab661a523652c 59484 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_amd64.deb b586b204d11b74c76865e86f080433ad 222264 net optional unbound-anchor_1.26.1-0+deb13u1_amd64.deb e3579ae4617876958a31fa998834c333 5770944 debug optional unbound-dbgsym_1.26.1-0+deb13u1_amd64.deb 4115a04198cc507607b572f484b49e18 132972 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_amd64.deb f2bbb095a7201ec42e92c4810a6484c5 244076 net optional unbound-host_1.26.1-0+deb13u1_amd64.deb 5a783526f38bafd9ca90491b57e1d93b 10600 net optional unbound_1.26.1-0+deb13u1_amd64-buildd.buildinfo 63864210fa4ee84f2f1bb37e9ced6ef8 1127212 net optional unbound_1.26.1-0+deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmqtZ8QACgkQYg9P9sm2 dfHfzRAA0AWhOicmAJJgI1pYbGvEApz9dpCIIAiICSrSKKSAsWifW8EF2tYIRs7d 5hpp1ULuxQgiWlR3Ka9e1pqPQy4nwjTdDNDfww8M133hYiHB8CbrMXUd3dS8U8wy 9iSUaccpKRhM+KRav79yAAMXQ7dpORBfncKDi69hgd1ubWRlTboAQEwuo42s1Zyg fwoOeDJ0Y+WZyDp+1R2xYdojV9fhvB3OCl6sIOc55Xu3Gyo1Vli+DNLrhGWwtupK oegY1e7kmsWeCzPh6Zpt7ez/xXaw6Clu+ClRVvIRqHW/SXR6l6cQr+I5uyXEo2Wb lCXhAc5b/wLse2944KKZbzU/QhuZoC+XolmMWJdgLRHnf2UCY+9VddO55HPdWV2q LyX9c/6nL+rcWv+Hl0YEChpTIZuORlOPxJssu4QvnDV2LkspbIVuOtXcShe7QkZ2 tfF5N1epeAQguv9cmPMXtm6BFO2AEhZk++L2U9iFOtNn464Q0FusCjGJKqyJRVZt kN4bNa63B6o16VkOePJWfOdnzCfY7NiUNJze+Non1qfxun9wWjZT9LACLD5vj78i X6vYrmQDT+tCUzpEgaXZj9r4FFceNvv/cKdDV/i/oFJuB9Km2L1Jjo35PSFH5UgL Sq3Z6ucxdD8OG9Y3eIsx4YUCm4AK3BhqWeF4z/EFBN1ogH7YFzE= =HOky -----END PGP SIGNATURE-----