-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Sep 2026 11:55:59 +0300 Source: unbound Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym Architecture: riscv64 Version: 1.26.1-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: riscv64 Build Daemon (rv-osuosl-01) Changed-By: Michael Tokarev Description: libunbound-dev - static library, header files, and docs for libunbound libunbound8 - library implementing DNS resolution and validation python3-unbound - library implementing DNS resolution and validation (Python3 bindi unbound - validating, recursive, caching DNS resolver unbound-anchor - utility to securely fetch the root DNS trust anchor unbound-host - reimplementation of the 'host' command Closes: 1096189 1142539 Changes: unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium . * New upstream release fixing numerous security and other issues and contains some enhancements. . Traditionally in Debian, bugs in stable versions are fixed by providing a back-port of a fix from later upstream version to the version in Debian stable. With unbound, fixes in subsequent versions can not be applied directly to the version in Debian stable, as there were multiple other code changes in these areas. Many of these changes fixes other issues (security or not). Some changes are in areas with complex logic, hence requires creat care when back-porting to older releases. And the result of such back-porting becomes unique and rather unpredictable. So instead of trying to provide fixes for older version in Debian stable, we decided to provide current upstream version of unbound, - the same as currently available in Debian Sid. The packaging is made very similar too. . Recent security fixes: . o CVE-2026-81642 - severity: CRITICAL Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY o CVE-2026-81634 - severity: HIGH Possible heap buffer overflow during DNSSEC canonicalization o CVE-2026-82717 - severity: HIGH CNAME synthesis could lead to heap corruption o CVE-2026-77955 - severity: MEDIUM Possible ZONEMD verification bypass window o CVE-2026-78227 - severity: MEDIUM Use-after-free in DoQ stream output buffer on reset re-transmission o CVE-2026-80225 - severity: MEDIUM Possible degradation of service from continuous queries on the same TCP/DoT connection o CVE-2026-82720 - severity: MEDIUM Use-after-free in DoH stream cleanup code path o CVE-2026-85501 - severity: MEDIUM Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC o CVE-2026-77860 - severity: LOW 'serve-expired' can bypass Unbound 'wait-limit' o CVE-2026-32665 - severity: HIGH Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass o CVE-2026-40691 - severity: HIGH Packet of death for DNSCrypt over TCP o CVE-2026-44690 - severity: HIGH Cross-zone wildcard cache poisoning via RRSIG.labels manipulation o CVE-2026-55973 - severity: HIGH 'dns-error-reporting: yes' leads to stack buffer overflow o CVE-2026-14586 - severity: MEDIUM Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments o CVE-2026-44621 - severity: MEDIUM Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated o CVE-2026-50045 - severity: MEDIUM 'max-global-quota' reset by DNSSEC validation restarts o CVE-2026-50046 - severity: MEDIUM Possible heap use-after-free in an error path when a DoT forwarded query is jostled out o CVE-2026-50243 - severity: MEDIUM response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL o CVE-2026-50248 - severity: MEDIUM BOGUS configured primary hostname accepted for XFR in auth/rpz zones o CVE-2026-50251 - severity: MEDIUM Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush o CVE-2026-50252 - severity: MEDIUM Possible cache poisoning attack by mapping source port population per thread o CVE-2026-52863 - severity: MEDIUM Memory corruption could lead to crash and denial of service o CVE-2026-55717 - severity: MEDIUM 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash o CVE-2026-55990 - severity: MEDIUM Packet of death for a DNSCrypt misconfigured Unbound o CVE-2026-55991 - severity: MEDIUM Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 o CVE-2026-56416 - severity: MEDIUM Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name o CVE-2026-56444 - severity: MEDIUM Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration o CVE-2026-41637 - severity: LOW Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries o CVE-2026-42955 - severity: LOW Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records o CVE-2026-44687 - severity: LOW Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN o CVE-2026-46582 - severity: LOW A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path o CVE-2026-54478 - severity: LOW DNS Cookie bypass when combined with proxy-protocol use o CVE-2026-55708 - severity: LOW Privacy/configuration issue when adding local data in views through 'unbound-control' . Other notable user-visible changes and fixes. For complete list, please see /usr/share/doc/unbound/changelog.gz . o ICANN Bundle Update: Refreshed icannbundle.pem certificates in unbound-anchor to include public keys valid for 2009–2029 and 2025–2045 o Transfer Limits: Added max-transfer-size and max-transfer-time directives to limit authorization zone (auth-zone) and RPZ transfer sizes and times to harden against unbounded transfers. o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA queries, plus block_a_wdata and block_aaaa_wdata to support custom local data fallback. o Management Improvements: Overloaded local_data_remove to allow the removal of precise records. o Fix for the Jiggle Attack. The server is fixed to answer with errors for error cases, and does not stay silent. In addition, the error replies do not contain parts of the incoming query. This is more conformant, stops reflection and stops it as a covert channel. o Fix EDNS extended RCODE reflection. This fixes that the server does not echo extended rcode values after class chaos queries. o Fix for iterator RCODE handling of YXDOMAIN. This fixes that the server only accepts YXDOMAIN answers that contain a DNAME record. This stops bad answers, and checks that the authoritative server gives correct replies. o Fix for missing bounds check for decompressing dnames for downloaded authority zones. This fixes that the server could end up with malformed zone content after receiving truncated packet contents from an AXFR. In addition, the domain names in the SOA rdata are checked before the authority code picks up the zone serial. o Fix that upstream TLS connections are not reused as TLS connections for a different name, at the same IP. This checks that the tls name is correct when reusing the upstream connections. o Fix that signatures are not allowed with revoked dnskeys. o Fix that a DNAME with an unsigned CNAME is checked for the correct match. This stops that for certain zone configurations an unchecked unsigned CNAME could get secure status. o Fix handling of wildcard CNAMEs in the chain of trust. An improper wildcard in the chain of trust would send the retries to the wrong upstream. Also it could label the step in the chain of trust as secure, when it was not. o Introduce new 'tls-protocols' configuration option that specifies which of the supported TLS protocols will be used. o Fix RFC7766 compliance when client sends EOF over TCP. It stops pending replies and closes. o Fix to shorten RRSIG count in scrubber, this protects against an overly large number of RRSIGs. It can be configured with `iter-scrub-rrsig: 8`, it has default 8. o Fix for EDNS client subnet so that it does not store SERVFAIL in the global cache after a failed lookup, such as timeouts. A failure entry is stored in the subnet cache, for the query name, for a couple of seconds. Queries can continue to use the subnet cache during that time. o Fix to allow the control-interface config to use ip@port notation. o Fix to check for invalid http content length and chunk size, and to check the RR rdata field lengths when decompressing and inserting RRs from an authority zone transfer. This stops large memory use and heap buffer-overflow read errors. o Fix to ignore out-of-zone DNAME records for CNAME synthesis. Fix so that a reload checks if the files have changed, and if so, reload the contexts. Also for DoH, DoQ and outgoing DoT. o Apply cache TTL policy to DNAME and synthesized CNAME on wire path. o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound. o Allow synthesized DNAME TTL=0 to be served from cache within grace period. The responses are served from cache within a 1-second grace period. Reduces recursion when authoritative servers return DNAME with TTL=0 (RFC 2308). Response still returns TTL=0 to clients. o On Linux systems log the system-wide unique thread ID instead of Unbound's internal thread counter. o Introduce the 'log-thread-id' configuration option to manage logging the system-wide Linux thread ID for easier debugging with system tools. o Mesh reply counters. This adds statistics num.queries.replyaddr_limit and requestlist.current.replies. o Add extra statistic to track the number of signature validation operations. Adds 'num.valops' to extended statistics. o Fix for cname chain length with qtype ANY and qname minimisation. o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where the UDP socket send buffers are exhausted waiting for ARP/NDP resolution. o Increase default to `num-queries-per-thread: 2048`, when unbound is compiled with libevent. It makes saturation of the task queue more resource intensive and less practical. o DNS Error Reporting (RFC 9567). Introduces new configuration option 'dns-error-reporting' and new statistics for 'num.dns_error_reports'. o Redis read-only replica support. Introduces new 'redis-replica-*' options for the Redis cache backend. o Exempt loopback addresses from wait-limit. o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse to allow two arguments. o Fast Reload. The unbound-control fast_reload is added. It reads changed config in a thread, then only briefly pauses the service threads, that keep running. DNS service is only interrupted briefly. o Make the default value of module-config "validator iterator" regardless of compilation options. --enable-subnet would implicitly change the value to enable the subnetcache module by default in the past. o Add unbound members group access to control key. o Add resolver.arpa and service.arpa to the default locally served zones. o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake. o Serve expired cache update fixes. Fixes a regression bug with serve-expired that appeared in 1.22.0 and would not allow the iterator to update the cache with not-yet-validated entries resulting in increased outgoing traffic. Closes: #1142539 o The default value of serve-expired-ttl is set to 86400 (1 day) as suggested by RFC8767. o Increase the default of max-global-quota to 200 from 128 after operational feedback. Still keeping the possible amplification factor (CAMP related issues) in the hundreds. o Fix for the serve expired DNSSEC information fix, it would not allow current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses. o Statistics for discard-timeout and wait-limit. . * Other packaging changes: - d/rules,d/libunbound-dev.install: drop static library and deps (Closes: #1096189) - unbound-helper: do not update resolvconf if it is systemd-resolved - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd - d/upstream/signing-key.asc: update with the new upstream key - d/unbound.conf.d/remote-control.conf: fix typo Checksums-Sha1: 28b6cc1298cb4204e96b6246e9ed9c294a7881c2 213576 libunbound-dev_1.26.1-0+deb13u1_riscv64.deb 06c7a8a8a07af441e9444065ed046f3b77b9e895 1356052 libunbound8-dbgsym_1.26.1-0+deb13u1_riscv64.deb 646fba7bd423aabf29c5afb25a1990fc33416d92 650216 libunbound8_1.26.1-0+deb13u1_riscv64.deb e5f4dc43b58fa682575c57864ef37c38730b4a33 149596 python3-unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb 3870b41caf8b1b233d3468264ca7522a9b184561 247716 python3-unbound_1.26.1-0+deb13u1_riscv64.deb 8e83f9773c7a37c2cfe9dca40290ccf1111ce8c7 57236 unbound-anchor-dbgsym_1.26.1-0+deb13u1_riscv64.deb 12cd2173ff0787e836217cc789760046b2284f2d 222036 unbound-anchor_1.26.1-0+deb13u1_riscv64.deb 0c4cd519b8652e0818ec8c2f38e394dd213e0593 5454252 unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb 19a317bfff7f0f862b081e1562f65bbd215460f4 128124 unbound-host-dbgsym_1.26.1-0+deb13u1_riscv64.deb c6bd51138588f57e2fb3e0ddecce8778799c54b3 246848 unbound-host_1.26.1-0+deb13u1_riscv64.deb 01cfe719cc35a94028fc3349e1555a7e7d29acf6 10598 unbound_1.26.1-0+deb13u1_riscv64-buildd.buildinfo f8dbf2405be879b0fe348a3594b162e0375a3712 1140240 unbound_1.26.1-0+deb13u1_riscv64.deb Checksums-Sha256: f545e36a21ecb45001be0159ea4d41cddc999fc731ddd742c39f713880d5af9a 213576 libunbound-dev_1.26.1-0+deb13u1_riscv64.deb bf4e837d18c84ad74fa2c3a70c18595491231143b175a58c9600bd5146b6a9a9 1356052 libunbound8-dbgsym_1.26.1-0+deb13u1_riscv64.deb db9a74a513d7fee8bf4cba0e45b3efec8b5f4f9f3d2851fff6301c97f128a587 650216 libunbound8_1.26.1-0+deb13u1_riscv64.deb aed229c09edeb7925c7db4ec349e595b5dda4457b081bedf022f6169099c54d6 149596 python3-unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb dd53b7d7bb2d9a709fabd627b15bf760e56fe2988ab0a7c701e0bdc2c63588bc 247716 python3-unbound_1.26.1-0+deb13u1_riscv64.deb bf4596dd734f01eed3fe09b64f0c82ef38170b2497a22266cff7e2e24155d856 57236 unbound-anchor-dbgsym_1.26.1-0+deb13u1_riscv64.deb e6140d6f7f88c9f490d52308d0395d26950f1757a6fa4c548e62fccc49c63ec5 222036 unbound-anchor_1.26.1-0+deb13u1_riscv64.deb ef57e8bca7b9055fb4fb81a22127340b16866d263c354a7d585e406354e21874 5454252 unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb 4e2d0069390fb1ba7ec3223b014d9a6a6c785bf6c264e197866c89af40997937 128124 unbound-host-dbgsym_1.26.1-0+deb13u1_riscv64.deb 68342e919c97b7b1b43698624f5e106f54e87077c6439fa5942a9e200e040e91 246848 unbound-host_1.26.1-0+deb13u1_riscv64.deb 62c49088382aa835db6b030a7edfcaf276d3a2549f2b2465077fec812d52f4d6 10598 unbound_1.26.1-0+deb13u1_riscv64-buildd.buildinfo 8b5c5d8c08c028f521846613c887a59836e97c5378561f73b55e7272b37ea2c5 1140240 unbound_1.26.1-0+deb13u1_riscv64.deb Files: d15c7aaa4c7c698feacc0a84dd2eb065 213576 libdevel optional libunbound-dev_1.26.1-0+deb13u1_riscv64.deb 188f60fae0cd08eecb04f9f4957bb523 1356052 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_riscv64.deb 15bddbda2219cd338953443dd29cdeeb 650216 libs optional libunbound8_1.26.1-0+deb13u1_riscv64.deb 3a55b495b302f8453f4618828646a406 149596 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb 55624fac66a6ec1799bfb0a0006d62c0 247716 python optional python3-unbound_1.26.1-0+deb13u1_riscv64.deb 4d38ddf85d33cb6d26f3c10235a1db38 57236 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_riscv64.deb 96a5fe905f92abc790df108abf7eb1bb 222036 net optional unbound-anchor_1.26.1-0+deb13u1_riscv64.deb 1b1bc282549d56b66e9982019bedd92c 5454252 debug optional unbound-dbgsym_1.26.1-0+deb13u1_riscv64.deb a0023020abe58dfdcdf3bd2a36f091be 128124 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_riscv64.deb 94fbc96e86178f148e53d3cc1c0fc0bc 246848 net optional unbound-host_1.26.1-0+deb13u1_riscv64.deb 04679f787ba538d14f1a7cac47304488 10598 net optional unbound_1.26.1-0+deb13u1_riscv64-buildd.buildinfo 5ace112650702891d5aaf59c1ccb3dba 1140240 net optional unbound_1.26.1-0+deb13u1_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3smN1vgomTkXJcrkIhSPlPtgqxkFAmqtb5QACgkQIhSPlPtg qxkZ1RAAt1hg4T6XL7LwWayoZv+MBvqkVEsSNMJyoc+X2uZiuFX1inFxloem2e3x PlDPylqfpWZAjg/b2QVTjNpYoLcNMgDY0L0hfHBmAc/45J1OAODp+CNW8Hxv7ukj qu4EiQ4Q8K4Isxow6Y3g0uxbn/wcvE3yYwN+DS7unjSM2CkjYISxGsFusWQqgNvO UIzojmc3zY8k+MS5NcipPSOwgFAtiHMN3O/IXtc/HNCodXfr2DGBbWAVCJBpcvhC pr0C7R76Yo+VrQKPdE8E1mT2XIEbR5kF9si3xV5Uj9fe1L4feWFCc9WuSptyjVz7 p+QPy9myL4iPt4vHRJu3LiPsZ+MjlD35zMiKKd62G6cQPd9tsC87paEQjy+v9L31 C/gQ7lNR/MU/rgXHgyT1EixwPDHeV2mIThwRz+jdK5lVtAHyeKGY13L//jXxYi6P gsBMVIHT1lPArDrR+3XCu/gKfM2F3ttGFWoc6/OHt5mYY5iIU/KqxRQjjfKTfgXx GQP7bc92lDYDyV5XRIdn8gtULnQmbfsFbZvh3bqK1k23IH6Af2mfS4BcUGqOZtDO SwCtzI6rFwe9QdQylq2YTqrF9u+fjOnE7XpLNHXA88DAVsFaEF4pRE3N1gP2xKis eREbXc58qc23R/gryAkQlXZS355WsCxHRKcQNGf3sHris/pxf88= =P6Lb -----END PGP SIGNATURE-----