-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Sep 2026 11:55:59 +0300 Source: unbound Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym Architecture: i386 Version: 1.26.1-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Michael Tokarev Description: libunbound-dev - static library, header files, and docs for libunbound libunbound8 - library implementing DNS resolution and validation python3-unbound - library implementing DNS resolution and validation (Python3 bindi unbound - validating, recursive, caching DNS resolver unbound-anchor - utility to securely fetch the root DNS trust anchor unbound-host - reimplementation of the 'host' command Closes: 1096189 1142539 Changes: unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium . * New upstream release fixing numerous security and other issues and contains some enhancements. . Traditionally in Debian, bugs in stable versions are fixed by providing a back-port of a fix from later upstream version to the version in Debian stable. With unbound, fixes in subsequent versions can not be applied directly to the version in Debian stable, as there were multiple other code changes in these areas. Many of these changes fixes other issues (security or not). Some changes are in areas with complex logic, hence requires creat care when back-porting to older releases. And the result of such back-porting becomes unique and rather unpredictable. So instead of trying to provide fixes for older version in Debian stable, we decided to provide current upstream version of unbound, - the same as currently available in Debian Sid. The packaging is made very similar too. . Recent security fixes: . o CVE-2026-81642 - severity: CRITICAL Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY o CVE-2026-81634 - severity: HIGH Possible heap buffer overflow during DNSSEC canonicalization o CVE-2026-82717 - severity: HIGH CNAME synthesis could lead to heap corruption o CVE-2026-77955 - severity: MEDIUM Possible ZONEMD verification bypass window o CVE-2026-78227 - severity: MEDIUM Use-after-free in DoQ stream output buffer on reset re-transmission o CVE-2026-80225 - severity: MEDIUM Possible degradation of service from continuous queries on the same TCP/DoT connection o CVE-2026-82720 - severity: MEDIUM Use-after-free in DoH stream cleanup code path o CVE-2026-85501 - severity: MEDIUM Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC o CVE-2026-77860 - severity: LOW 'serve-expired' can bypass Unbound 'wait-limit' o CVE-2026-32665 - severity: HIGH Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass o CVE-2026-40691 - severity: HIGH Packet of death for DNSCrypt over TCP o CVE-2026-44690 - severity: HIGH Cross-zone wildcard cache poisoning via RRSIG.labels manipulation o CVE-2026-55973 - severity: HIGH 'dns-error-reporting: yes' leads to stack buffer overflow o CVE-2026-14586 - severity: MEDIUM Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments o CVE-2026-44621 - severity: MEDIUM Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated o CVE-2026-50045 - severity: MEDIUM 'max-global-quota' reset by DNSSEC validation restarts o CVE-2026-50046 - severity: MEDIUM Possible heap use-after-free in an error path when a DoT forwarded query is jostled out o CVE-2026-50243 - severity: MEDIUM response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL o CVE-2026-50248 - severity: MEDIUM BOGUS configured primary hostname accepted for XFR in auth/rpz zones o CVE-2026-50251 - severity: MEDIUM Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush o CVE-2026-50252 - severity: MEDIUM Possible cache poisoning attack by mapping source port population per thread o CVE-2026-52863 - severity: MEDIUM Memory corruption could lead to crash and denial of service o CVE-2026-55717 - severity: MEDIUM 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash o CVE-2026-55990 - severity: MEDIUM Packet of death for a DNSCrypt misconfigured Unbound o CVE-2026-55991 - severity: MEDIUM Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 o CVE-2026-56416 - severity: MEDIUM Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name o CVE-2026-56444 - severity: MEDIUM Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration o CVE-2026-41637 - severity: LOW Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries o CVE-2026-42955 - severity: LOW Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records o CVE-2026-44687 - severity: LOW Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN o CVE-2026-46582 - severity: LOW A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path o CVE-2026-54478 - severity: LOW DNS Cookie bypass when combined with proxy-protocol use o CVE-2026-55708 - severity: LOW Privacy/configuration issue when adding local data in views through 'unbound-control' . Other notable user-visible changes and fixes. For complete list, please see /usr/share/doc/unbound/changelog.gz . o ICANN Bundle Update: Refreshed icannbundle.pem certificates in unbound-anchor to include public keys valid for 2009–2029 and 2025–2045 o Transfer Limits: Added max-transfer-size and max-transfer-time directives to limit authorization zone (auth-zone) and RPZ transfer sizes and times to harden against unbounded transfers. o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA queries, plus block_a_wdata and block_aaaa_wdata to support custom local data fallback. o Management Improvements: Overloaded local_data_remove to allow the removal of precise records. o Fix for the Jiggle Attack. The server is fixed to answer with errors for error cases, and does not stay silent. In addition, the error replies do not contain parts of the incoming query. This is more conformant, stops reflection and stops it as a covert channel. o Fix EDNS extended RCODE reflection. This fixes that the server does not echo extended rcode values after class chaos queries. o Fix for iterator RCODE handling of YXDOMAIN. This fixes that the server only accepts YXDOMAIN answers that contain a DNAME record. This stops bad answers, and checks that the authoritative server gives correct replies. o Fix for missing bounds check for decompressing dnames for downloaded authority zones. This fixes that the server could end up with malformed zone content after receiving truncated packet contents from an AXFR. In addition, the domain names in the SOA rdata are checked before the authority code picks up the zone serial. o Fix that upstream TLS connections are not reused as TLS connections for a different name, at the same IP. This checks that the tls name is correct when reusing the upstream connections. o Fix that signatures are not allowed with revoked dnskeys. o Fix that a DNAME with an unsigned CNAME is checked for the correct match. This stops that for certain zone configurations an unchecked unsigned CNAME could get secure status. o Fix handling of wildcard CNAMEs in the chain of trust. An improper wildcard in the chain of trust would send the retries to the wrong upstream. Also it could label the step in the chain of trust as secure, when it was not. o Introduce new 'tls-protocols' configuration option that specifies which of the supported TLS protocols will be used. o Fix RFC7766 compliance when client sends EOF over TCP. It stops pending replies and closes. o Fix to shorten RRSIG count in scrubber, this protects against an overly large number of RRSIGs. It can be configured with `iter-scrub-rrsig: 8`, it has default 8. o Fix for EDNS client subnet so that it does not store SERVFAIL in the global cache after a failed lookup, such as timeouts. A failure entry is stored in the subnet cache, for the query name, for a couple of seconds. Queries can continue to use the subnet cache during that time. o Fix to allow the control-interface config to use ip@port notation. o Fix to check for invalid http content length and chunk size, and to check the RR rdata field lengths when decompressing and inserting RRs from an authority zone transfer. This stops large memory use and heap buffer-overflow read errors. o Fix to ignore out-of-zone DNAME records for CNAME synthesis. Fix so that a reload checks if the files have changed, and if so, reload the contexts. Also for DoH, DoQ and outgoing DoT. o Apply cache TTL policy to DNAME and synthesized CNAME on wire path. o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound. o Allow synthesized DNAME TTL=0 to be served from cache within grace period. The responses are served from cache within a 1-second grace period. Reduces recursion when authoritative servers return DNAME with TTL=0 (RFC 2308). Response still returns TTL=0 to clients. o On Linux systems log the system-wide unique thread ID instead of Unbound's internal thread counter. o Introduce the 'log-thread-id' configuration option to manage logging the system-wide Linux thread ID for easier debugging with system tools. o Mesh reply counters. This adds statistics num.queries.replyaddr_limit and requestlist.current.replies. o Add extra statistic to track the number of signature validation operations. Adds 'num.valops' to extended statistics. o Fix for cname chain length with qtype ANY and qname minimisation. o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where the UDP socket send buffers are exhausted waiting for ARP/NDP resolution. o Increase default to `num-queries-per-thread: 2048`, when unbound is compiled with libevent. It makes saturation of the task queue more resource intensive and less practical. o DNS Error Reporting (RFC 9567). Introduces new configuration option 'dns-error-reporting' and new statistics for 'num.dns_error_reports'. o Redis read-only replica support. Introduces new 'redis-replica-*' options for the Redis cache backend. o Exempt loopback addresses from wait-limit. o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse to allow two arguments. o Fast Reload. The unbound-control fast_reload is added. It reads changed config in a thread, then only briefly pauses the service threads, that keep running. DNS service is only interrupted briefly. o Make the default value of module-config "validator iterator" regardless of compilation options. --enable-subnet would implicitly change the value to enable the subnetcache module by default in the past. o Add unbound members group access to control key. o Add resolver.arpa and service.arpa to the default locally served zones. o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake. o Serve expired cache update fixes. Fixes a regression bug with serve-expired that appeared in 1.22.0 and would not allow the iterator to update the cache with not-yet-validated entries resulting in increased outgoing traffic. Closes: #1142539 o The default value of serve-expired-ttl is set to 86400 (1 day) as suggested by RFC8767. o Increase the default of max-global-quota to 200 from 128 after operational feedback. Still keeping the possible amplification factor (CAMP related issues) in the hundreds. o Fix for the serve expired DNSSEC information fix, it would not allow current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses. o Statistics for discard-timeout and wait-limit. . * Other packaging changes: - d/rules,d/libunbound-dev.install: drop static library and deps (Closes: #1096189) - unbound-helper: do not update resolvconf if it is systemd-resolved - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd - d/upstream/signing-key.asc: update with the new upstream key - d/unbound.conf.d/remote-control.conf: fix typo Checksums-Sha1: ec7e8c707f92272ea48cb412ef2e00c035198869 213584 libunbound-dev_1.26.1-0+deb13u1_i386.deb 7b71a38108dd865bed1ef6db3d88582025e1c14d 1223220 libunbound8-dbgsym_1.26.1-0+deb13u1_i386.deb 2b63137de48bebc7cbfd60b57f4aaa2f393c5051 679552 libunbound8_1.26.1-0+deb13u1_i386.deb 9b7eab6ade431b09df6cdd8766fc7945ef2638ed 158692 python3-unbound-dbgsym_1.26.1-0+deb13u1_i386.deb aedf8b2ebaef4846388604258c7b99a19ec9b31d 248780 python3-unbound_1.26.1-0+deb13u1_i386.deb fe023acb512a09704cdc68fefbac7983cb80010d 56740 unbound-anchor-dbgsym_1.26.1-0+deb13u1_i386.deb 1f59afd3dea266013d0bf0a22d42b4db6d0e605a 225208 unbound-anchor_1.26.1-0+deb13u1_i386.deb 1e5fc0df1f421ece23390487485f4ac5aff2f0f7 5080284 unbound-dbgsym_1.26.1-0+deb13u1_i386.deb 63ce3647f104f71623d978d0a8c6a4a2a96c816c 113844 unbound-host-dbgsym_1.26.1-0+deb13u1_i386.deb ae0ede0a3fbb00272a9a28c9cb17fa421bdb20e6 248104 unbound-host_1.26.1-0+deb13u1_i386.deb a55398f4985e82c0384867c6252603caaf50f4df 10474 unbound_1.26.1-0+deb13u1_i386-buildd.buildinfo 92f07a6da875fd033583c236ad0799187cdf6f9f 1168732 unbound_1.26.1-0+deb13u1_i386.deb Checksums-Sha256: 17ba3214ea8ba1b6ad784b064be5ff1fdef85931210c0893a98ffb64730e662d 213584 libunbound-dev_1.26.1-0+deb13u1_i386.deb 7bdb9ed2c07e2f87e1023835a406c6d67450cb2d28380d558ab1267a5c712534 1223220 libunbound8-dbgsym_1.26.1-0+deb13u1_i386.deb 5bbec4ce1551a2505f799805469015b876a525a4abab1d82126dc777428cb07f 679552 libunbound8_1.26.1-0+deb13u1_i386.deb 818ecdac9c232062cfde3ca5496819dc7563ba2dbcb956354cf09dd0735b21fb 158692 python3-unbound-dbgsym_1.26.1-0+deb13u1_i386.deb 42934e7245087ce197036163d1bb61980c5b8ccec579b553c1cf04e201faf383 248780 python3-unbound_1.26.1-0+deb13u1_i386.deb ddc17cb1deffad3a9f6e96f3804b92009727b2131cab8e61bb7e81a1a34c34cc 56740 unbound-anchor-dbgsym_1.26.1-0+deb13u1_i386.deb f8aa272488bdc2f32a0a525bf488a03c476d4abdabe7461e01fde48c7bad889f 225208 unbound-anchor_1.26.1-0+deb13u1_i386.deb 877685a504c9411621e9a85ef86e4ecbb3065d1c888db5f169a6d870e8d63285 5080284 unbound-dbgsym_1.26.1-0+deb13u1_i386.deb 796aae1ed82cff7b38f916abcf10b61c8139e7a0f5875a853754e503eba35c78 113844 unbound-host-dbgsym_1.26.1-0+deb13u1_i386.deb d2466d8bcd9b5b939e54ec7970483f4eacef4065f9d6bf7c23e860e05abfcd5a 248104 unbound-host_1.26.1-0+deb13u1_i386.deb e4bbac1d07bbe8978874da908bd8eefcbeeda81d8fca1dc823a061743466177f 10474 unbound_1.26.1-0+deb13u1_i386-buildd.buildinfo 356215474d97ebf54085c4bbbbff63bb392bad6a8399be64c4aa069db5e97f1a 1168732 unbound_1.26.1-0+deb13u1_i386.deb Files: 7a64455a19a6e5b3bdb7febf11ee9bc7 213584 libdevel optional libunbound-dev_1.26.1-0+deb13u1_i386.deb 1ce5cacc16c869bffcd5df0b626aaaad 1223220 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_i386.deb 1a2903d51081051238d6cc97b85c9584 679552 libs optional libunbound8_1.26.1-0+deb13u1_i386.deb d686fc013b62c30139e9a0f9fc9d4722 158692 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_i386.deb 5f33973f41c92238f3d61fdd7c152c7d 248780 python optional python3-unbound_1.26.1-0+deb13u1_i386.deb 80b221e44539872990fc23989e33ce06 56740 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_i386.deb a4eb4eff7d20a1376762cb41a65ed2d4 225208 net optional unbound-anchor_1.26.1-0+deb13u1_i386.deb 8640193cba766fcf61f6de175e32020e 5080284 debug optional unbound-dbgsym_1.26.1-0+deb13u1_i386.deb 66e7ffd1c6dc3ace25e8ad9b8b1aeabb 113844 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_i386.deb f4e6abe359768e4e02619f01781544e1 248104 net optional unbound-host_1.26.1-0+deb13u1_i386.deb c883443de82d197296cbdca357a7f422 10474 net optional unbound_1.26.1-0+deb13u1_i386-buildd.buildinfo dc1a0831f4f6c381a89dabf0a5f16bbd 1168732 net optional unbound_1.26.1-0+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmqtaLUACgkQN8Ugyu9d QiTGVQ//eEQQucsdikaBT8233lSokrjZHSA5RPrtMqVQaDW4Hh16IigcFTrLj1fG I45N2aVkr5xkxMy8egQRgTQCvi1N05eeswJl14uloHcczBLSwD36ppxNW9SvefE2 88iFbgy3y8i+4tRo0il8XDSdgLZD/hSUdKe2NPJXM72p8qJb+pK5PTJkQDYi2yr4 6dRKxjuIPNsDrcGpLLuhmS9LeZCPQpBcPNpjAQhLF7C9dolTovSQLhgTBYNMPKiB Jhm+NiFNJ6UkQVohlBrgk2z3m9+qABh7jXNZWw7REaL3vdh6Jg8gjqJcqQM7QHBi ONkou/RcbHRJTGn83KKfohgUu6w2X6iaETzm9UuX+hLAZSAeNuxxm12+xbNESf0l MwQDDbCLCtw7xgdvXuXQmb/dEtRP2q4FpDp/Bj/OHQTdxaUZcLxn3FlGrD2kQS76 CsUNMNshpeHaUJrKs/VG3yKSTPPYkNwqGCL6hyGJcwbyUIlsEokvufxDmaOuG0gJ GWE0jgAuNb9ltjqz/PAbWEnmMMpDyC+uryi7RK75pKXvrlNOqUhPcF0oyMYfdRJ+ cTkUSlb0wmS+Jlq/Bajg6wQ+LP4r9KRIf9RPlxKG5bfUW6GN0DiwzrqFU7QhuTOH 5RuwOb+VunQwOTjUh+JDT8ZSMSDqQgLcueuWKBKvrgwrkPaJJs4= =mBNl -----END PGP SIGNATURE-----