-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Sep 2026 11:55:59 +0300 Source: unbound Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym Architecture: ppc64el Version: 1.26.1-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Michael Tokarev Description: libunbound-dev - static library, header files, and docs for libunbound libunbound8 - library implementing DNS resolution and validation python3-unbound - library implementing DNS resolution and validation (Python3 bindi unbound - validating, recursive, caching DNS resolver unbound-anchor - utility to securely fetch the root DNS trust anchor unbound-host - reimplementation of the 'host' command Closes: 1096189 1142539 Changes: unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium . * New upstream release fixing numerous security and other issues and contains some enhancements. . Traditionally in Debian, bugs in stable versions are fixed by providing a back-port of a fix from later upstream version to the version in Debian stable. With unbound, fixes in subsequent versions can not be applied directly to the version in Debian stable, as there were multiple other code changes in these areas. Many of these changes fixes other issues (security or not). Some changes are in areas with complex logic, hence requires creat care when back-porting to older releases. And the result of such back-porting becomes unique and rather unpredictable. So instead of trying to provide fixes for older version in Debian stable, we decided to provide current upstream version of unbound, - the same as currently available in Debian Sid. The packaging is made very similar too. . Recent security fixes: . o CVE-2026-81642 - severity: CRITICAL Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY o CVE-2026-81634 - severity: HIGH Possible heap buffer overflow during DNSSEC canonicalization o CVE-2026-82717 - severity: HIGH CNAME synthesis could lead to heap corruption o CVE-2026-77955 - severity: MEDIUM Possible ZONEMD verification bypass window o CVE-2026-78227 - severity: MEDIUM Use-after-free in DoQ stream output buffer on reset re-transmission o CVE-2026-80225 - severity: MEDIUM Possible degradation of service from continuous queries on the same TCP/DoT connection o CVE-2026-82720 - severity: MEDIUM Use-after-free in DoH stream cleanup code path o CVE-2026-85501 - severity: MEDIUM Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC o CVE-2026-77860 - severity: LOW 'serve-expired' can bypass Unbound 'wait-limit' o CVE-2026-32665 - severity: HIGH Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass o CVE-2026-40691 - severity: HIGH Packet of death for DNSCrypt over TCP o CVE-2026-44690 - severity: HIGH Cross-zone wildcard cache poisoning via RRSIG.labels manipulation o CVE-2026-55973 - severity: HIGH 'dns-error-reporting: yes' leads to stack buffer overflow o CVE-2026-14586 - severity: MEDIUM Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments o CVE-2026-44621 - severity: MEDIUM Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated o CVE-2026-50045 - severity: MEDIUM 'max-global-quota' reset by DNSSEC validation restarts o CVE-2026-50046 - severity: MEDIUM Possible heap use-after-free in an error path when a DoT forwarded query is jostled out o CVE-2026-50243 - severity: MEDIUM response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL o CVE-2026-50248 - severity: MEDIUM BOGUS configured primary hostname accepted for XFR in auth/rpz zones o CVE-2026-50251 - severity: MEDIUM Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush o CVE-2026-50252 - severity: MEDIUM Possible cache poisoning attack by mapping source port population per thread o CVE-2026-52863 - severity: MEDIUM Memory corruption could lead to crash and denial of service o CVE-2026-55717 - severity: MEDIUM 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash o CVE-2026-55990 - severity: MEDIUM Packet of death for a DNSCrypt misconfigured Unbound o CVE-2026-55991 - severity: MEDIUM Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 o CVE-2026-56416 - severity: MEDIUM Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name o CVE-2026-56444 - severity: MEDIUM Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration o CVE-2026-41637 - severity: LOW Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries o CVE-2026-42955 - severity: LOW Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records o CVE-2026-44687 - severity: LOW Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN o CVE-2026-46582 - severity: LOW A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path o CVE-2026-54478 - severity: LOW DNS Cookie bypass when combined with proxy-protocol use o CVE-2026-55708 - severity: LOW Privacy/configuration issue when adding local data in views through 'unbound-control' . Other notable user-visible changes and fixes. For complete list, please see /usr/share/doc/unbound/changelog.gz . o ICANN Bundle Update: Refreshed icannbundle.pem certificates in unbound-anchor to include public keys valid for 2009–2029 and 2025–2045 o Transfer Limits: Added max-transfer-size and max-transfer-time directives to limit authorization zone (auth-zone) and RPZ transfer sizes and times to harden against unbounded transfers. o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA queries, plus block_a_wdata and block_aaaa_wdata to support custom local data fallback. o Management Improvements: Overloaded local_data_remove to allow the removal of precise records. o Fix for the Jiggle Attack. The server is fixed to answer with errors for error cases, and does not stay silent. In addition, the error replies do not contain parts of the incoming query. This is more conformant, stops reflection and stops it as a covert channel. o Fix EDNS extended RCODE reflection. This fixes that the server does not echo extended rcode values after class chaos queries. o Fix for iterator RCODE handling of YXDOMAIN. This fixes that the server only accepts YXDOMAIN answers that contain a DNAME record. This stops bad answers, and checks that the authoritative server gives correct replies. o Fix for missing bounds check for decompressing dnames for downloaded authority zones. This fixes that the server could end up with malformed zone content after receiving truncated packet contents from an AXFR. In addition, the domain names in the SOA rdata are checked before the authority code picks up the zone serial. o Fix that upstream TLS connections are not reused as TLS connections for a different name, at the same IP. This checks that the tls name is correct when reusing the upstream connections. o Fix that signatures are not allowed with revoked dnskeys. o Fix that a DNAME with an unsigned CNAME is checked for the correct match. This stops that for certain zone configurations an unchecked unsigned CNAME could get secure status. o Fix handling of wildcard CNAMEs in the chain of trust. An improper wildcard in the chain of trust would send the retries to the wrong upstream. Also it could label the step in the chain of trust as secure, when it was not. o Introduce new 'tls-protocols' configuration option that specifies which of the supported TLS protocols will be used. o Fix RFC7766 compliance when client sends EOF over TCP. It stops pending replies and closes. o Fix to shorten RRSIG count in scrubber, this protects against an overly large number of RRSIGs. It can be configured with `iter-scrub-rrsig: 8`, it has default 8. o Fix for EDNS client subnet so that it does not store SERVFAIL in the global cache after a failed lookup, such as timeouts. A failure entry is stored in the subnet cache, for the query name, for a couple of seconds. Queries can continue to use the subnet cache during that time. o Fix to allow the control-interface config to use ip@port notation. o Fix to check for invalid http content length and chunk size, and to check the RR rdata field lengths when decompressing and inserting RRs from an authority zone transfer. This stops large memory use and heap buffer-overflow read errors. o Fix to ignore out-of-zone DNAME records for CNAME synthesis. Fix so that a reload checks if the files have changed, and if so, reload the contexts. Also for DoH, DoQ and outgoing DoT. o Apply cache TTL policy to DNAME and synthesized CNAME on wire path. o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound. o Allow synthesized DNAME TTL=0 to be served from cache within grace period. The responses are served from cache within a 1-second grace period. Reduces recursion when authoritative servers return DNAME with TTL=0 (RFC 2308). Response still returns TTL=0 to clients. o On Linux systems log the system-wide unique thread ID instead of Unbound's internal thread counter. o Introduce the 'log-thread-id' configuration option to manage logging the system-wide Linux thread ID for easier debugging with system tools. o Mesh reply counters. This adds statistics num.queries.replyaddr_limit and requestlist.current.replies. o Add extra statistic to track the number of signature validation operations. Adds 'num.valops' to extended statistics. o Fix for cname chain length with qtype ANY and qname minimisation. o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where the UDP socket send buffers are exhausted waiting for ARP/NDP resolution. o Increase default to `num-queries-per-thread: 2048`, when unbound is compiled with libevent. It makes saturation of the task queue more resource intensive and less practical. o DNS Error Reporting (RFC 9567). Introduces new configuration option 'dns-error-reporting' and new statistics for 'num.dns_error_reports'. o Redis read-only replica support. Introduces new 'redis-replica-*' options for the Redis cache backend. o Exempt loopback addresses from wait-limit. o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse to allow two arguments. o Fast Reload. The unbound-control fast_reload is added. It reads changed config in a thread, then only briefly pauses the service threads, that keep running. DNS service is only interrupted briefly. o Make the default value of module-config "validator iterator" regardless of compilation options. --enable-subnet would implicitly change the value to enable the subnetcache module by default in the past. o Add unbound members group access to control key. o Add resolver.arpa and service.arpa to the default locally served zones. o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake. o Serve expired cache update fixes. Fixes a regression bug with serve-expired that appeared in 1.22.0 and would not allow the iterator to update the cache with not-yet-validated entries resulting in increased outgoing traffic. Closes: #1142539 o The default value of serve-expired-ttl is set to 86400 (1 day) as suggested by RFC8767. o Increase the default of max-global-quota to 200 from 128 after operational feedback. Still keeping the possible amplification factor (CAMP related issues) in the hundreds. o Fix for the serve expired DNSSEC information fix, it would not allow current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses. o Statistics for discard-timeout and wait-limit. . * Other packaging changes: - d/rules,d/libunbound-dev.install: drop static library and deps (Closes: #1096189) - unbound-helper: do not update resolvconf if it is systemd-resolved - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd - d/upstream/signing-key.asc: update with the new upstream key - d/unbound.conf.d/remote-control.conf: fix typo Checksums-Sha1: 99797d65783bddfe14352281b06a5308da63755b 213588 libunbound-dev_1.26.1-0+deb13u1_ppc64el.deb 0ddd920c08ace984674a945dd2533e16029ddebd 1449724 libunbound8-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 4245d128f0a1b7202c57c3e06d9f79e0506f20c2 669952 libunbound8_1.26.1-0+deb13u1_ppc64el.deb 22cae5ed754f1f6675f6bdb7f313ca9bc9a3b07a 168704 python3-unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 3bfede809814eb8605193a7f599fb7db8cd73bd5 248128 python3-unbound_1.26.1-0+deb13u1_ppc64el.deb a7414cce7c4f0cf01fa75824310087359f40d595 61044 unbound-anchor-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 32fbcedee31fe5d7019b7b60cd8b1a8768c93cb1 223380 unbound-anchor_1.26.1-0+deb13u1_ppc64el.deb 9bd07566d698dedcb5611fb93893e2d6c78aec20 5299200 unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 950b4468e1974902911b53bef0aad03e1f740112 137316 unbound-host-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 708f5ceb158d5a21bc77ee8c77c28fcb9d1731f5 250932 unbound-host_1.26.1-0+deb13u1_ppc64el.deb 0ff2c2f89067ca48d160f19e843c9bbdc1b3ac06 10653 unbound_1.26.1-0+deb13u1_ppc64el-buildd.buildinfo f27661ee3349128e16072545f43e316fb8e9a769 1133728 unbound_1.26.1-0+deb13u1_ppc64el.deb Checksums-Sha256: 5f5c074a78cf9009db59660c88b7280131664c92d13777cd9fa8871abfd20502 213588 libunbound-dev_1.26.1-0+deb13u1_ppc64el.deb 031a41284694bd7485d9ca3a0929b91bf5e5f9cc60a77734a0eea72f5eb603b7 1449724 libunbound8-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 7e8fdbcc685baa5d23e9dbed81f6b838f2b8f281b840d314cda45e2958e77c1e 669952 libunbound8_1.26.1-0+deb13u1_ppc64el.deb 089ed57c90f3e34a7df9d2d42fb73e076b058e82ffa717760fb817a60dc01739 168704 python3-unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 8221494c6f8247ba2d96058d3a6458ac90ad9fcd1f8ce4213352d4103dd908c6 248128 python3-unbound_1.26.1-0+deb13u1_ppc64el.deb 8cd2c25d64ba54208df6c10580e118840a03e34a43a6f1b17def9edd454fdfa3 61044 unbound-anchor-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 2295e1487c8ef13dd3d1e45fbf1d02da5aeb237660c494231b6898057af77607 223380 unbound-anchor_1.26.1-0+deb13u1_ppc64el.deb fddc1b53c55ab490ef674ec78da710a404743766118bc8fffd1a566c7835cbe8 5299200 unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 70eaeed98d404c74ede1699d0530896aca190b77e7d383f8096e54e61841f780 137316 unbound-host-dbgsym_1.26.1-0+deb13u1_ppc64el.deb d4f4d86b4e006bc79628125c577ecb5dbb36452211afa9af9fe437f784b852f3 250932 unbound-host_1.26.1-0+deb13u1_ppc64el.deb 80add92a50916228aa72ddd3b9ca595047e0a5b3a91f2d2aa13083b843ca9eb6 10653 unbound_1.26.1-0+deb13u1_ppc64el-buildd.buildinfo 0ee443722b3fbeaab16b9b0256ffecb45c454b369069eb2e914c18dc59095470 1133728 unbound_1.26.1-0+deb13u1_ppc64el.deb Files: 8f71d9788fcf1bf219ba752a98b727d5 213588 libdevel optional libunbound-dev_1.26.1-0+deb13u1_ppc64el.deb bed18b6e73e00ed39807a5a21b3531d9 1449724 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 6ce2c37d8c8e6ae8602aee54405c7792 669952 libs optional libunbound8_1.26.1-0+deb13u1_ppc64el.deb b5ac3aa539c781f292d073cf9e4e593a 168704 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 6cf40a749c72f0670729902c9e82cfe7 248128 python optional python3-unbound_1.26.1-0+deb13u1_ppc64el.deb 51cc7ee2d570a8f2fd1a37711e757f7b 61044 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 2aa17c63cd7879ce0fbc3314c9dd6b21 223380 net optional unbound-anchor_1.26.1-0+deb13u1_ppc64el.deb 10bf98bcacc9636eccdd048a25e37ae4 5299200 debug optional unbound-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 5c61b8f56bb0b4e65192d08041c279b8 137316 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_ppc64el.deb 86d85cec2c112c410011ea04dcb14ac7 250932 net optional unbound-host_1.26.1-0+deb13u1_ppc64el.deb 36069a76be0c0ab3805448a73cb975a3 10653 net optional unbound_1.26.1-0+deb13u1_ppc64el-buildd.buildinfo 394ad8cdaf6f661e3958c0ba43652925 1133728 net optional unbound_1.26.1-0+deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9ibmwdV9gdKNbK7oV8ucRsMTpuMFAmqtZ0MACgkQV8ucRsMT puMAvA/9GoHKLiu2MgbkFY0NTvC4Qk4AwurzE5NUNzcLfiicE82EAJH+o3cmvwoD NNb49l3OEZvFhsL3JT/aXwNXCMScF1p8m3+LHp6tK5fcG7LouIEmgdawc5t7r7EM nPDgFtz+rUBbM9y1w0mTIVYpJImcCfgeaNSn0ZRCsS3RcRzXb6mvXb0O3LmzKsUN cgyTB+8eJAeu5sEyshEq7OHueFEj/d3ygW+e0MJesl/Ne32fyVMEbQkm7ot5q5LP 7IClG92GghqfnihJ8hVsLODyUWWMMKQuwuwVWpEUNwKs7sK/uwmZINFCASCoq+H4 ENnndTEWI5XgNSriXKn94jI9uZqfEdQIJbuudBWpdW5SG+eKdgD2TeFVjG2fUhBB 8paeMAdsiagB8zAAcYaruKjdzwyBuEb8Ownephm4JD5HXVZInu93wKoFXLdpdvYT t+hHnDPMTX60ryC7NE99NI5Vct7rp6Ld3wfx+3nsc2BBokhGyY7AaK8pcVW+XmrM AIywu6IMycmFKFNz12kVW5cqv4dZRDJ/iKLBe1lfP8gGWIqot2sHEzyeeR0cTbGN CtqJMB281xhADFy6GUB8zbcm2Ojpx0cNHLAlKnN5eYnhshjXFqRWXGDLA9Rw8mKJ lVgvMe3rkqDAfNaAcW76aKStgda2aDjdjs8UD6w/cOhC0DdDyZU= =qfGZ -----END PGP SIGNATURE-----