-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Sep 2026 11:55:59 +0300 Source: unbound Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym Architecture: armhf Version: 1.26.1-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-06) Changed-By: Michael Tokarev Description: libunbound-dev - static library, header files, and docs for libunbound libunbound8 - library implementing DNS resolution and validation python3-unbound - library implementing DNS resolution and validation (Python3 bindi unbound - validating, recursive, caching DNS resolver unbound-anchor - utility to securely fetch the root DNS trust anchor unbound-host - reimplementation of the 'host' command Closes: 1096189 1142539 Changes: unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium . * New upstream release fixing numerous security and other issues and contains some enhancements. . Traditionally in Debian, bugs in stable versions are fixed by providing a back-port of a fix from later upstream version to the version in Debian stable. With unbound, fixes in subsequent versions can not be applied directly to the version in Debian stable, as there were multiple other code changes in these areas. Many of these changes fixes other issues (security or not). Some changes are in areas with complex logic, hence requires creat care when back-porting to older releases. And the result of such back-porting becomes unique and rather unpredictable. So instead of trying to provide fixes for older version in Debian stable, we decided to provide current upstream version of unbound, - the same as currently available in Debian Sid. The packaging is made very similar too. . Recent security fixes: . o CVE-2026-81642 - severity: CRITICAL Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY o CVE-2026-81634 - severity: HIGH Possible heap buffer overflow during DNSSEC canonicalization o CVE-2026-82717 - severity: HIGH CNAME synthesis could lead to heap corruption o CVE-2026-77955 - severity: MEDIUM Possible ZONEMD verification bypass window o CVE-2026-78227 - severity: MEDIUM Use-after-free in DoQ stream output buffer on reset re-transmission o CVE-2026-80225 - severity: MEDIUM Possible degradation of service from continuous queries on the same TCP/DoT connection o CVE-2026-82720 - severity: MEDIUM Use-after-free in DoH stream cleanup code path o CVE-2026-85501 - severity: MEDIUM Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC o CVE-2026-77860 - severity: LOW 'serve-expired' can bypass Unbound 'wait-limit' o CVE-2026-32665 - severity: HIGH Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass o CVE-2026-40691 - severity: HIGH Packet of death for DNSCrypt over TCP o CVE-2026-44690 - severity: HIGH Cross-zone wildcard cache poisoning via RRSIG.labels manipulation o CVE-2026-55973 - severity: HIGH 'dns-error-reporting: yes' leads to stack buffer overflow o CVE-2026-14586 - severity: MEDIUM Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments o CVE-2026-44621 - severity: MEDIUM Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated o CVE-2026-50045 - severity: MEDIUM 'max-global-quota' reset by DNSSEC validation restarts o CVE-2026-50046 - severity: MEDIUM Possible heap use-after-free in an error path when a DoT forwarded query is jostled out o CVE-2026-50243 - severity: MEDIUM response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL o CVE-2026-50248 - severity: MEDIUM BOGUS configured primary hostname accepted for XFR in auth/rpz zones o CVE-2026-50251 - severity: MEDIUM Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush o CVE-2026-50252 - severity: MEDIUM Possible cache poisoning attack by mapping source port population per thread o CVE-2026-52863 - severity: MEDIUM Memory corruption could lead to crash and denial of service o CVE-2026-55717 - severity: MEDIUM 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash o CVE-2026-55990 - severity: MEDIUM Packet of death for a DNSCrypt misconfigured Unbound o CVE-2026-55991 - severity: MEDIUM Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 o CVE-2026-56416 - severity: MEDIUM Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name o CVE-2026-56444 - severity: MEDIUM Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration o CVE-2026-41637 - severity: LOW Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries o CVE-2026-42955 - severity: LOW Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records o CVE-2026-44687 - severity: LOW Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN o CVE-2026-46582 - severity: LOW A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path o CVE-2026-54478 - severity: LOW DNS Cookie bypass when combined with proxy-protocol use o CVE-2026-55708 - severity: LOW Privacy/configuration issue when adding local data in views through 'unbound-control' . Other notable user-visible changes and fixes. For complete list, please see /usr/share/doc/unbound/changelog.gz . o ICANN Bundle Update: Refreshed icannbundle.pem certificates in unbound-anchor to include public keys valid for 2009–2029 and 2025–2045 o Transfer Limits: Added max-transfer-size and max-transfer-time directives to limit authorization zone (auth-zone) and RPZ transfer sizes and times to harden against unbounded transfers. o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA queries, plus block_a_wdata and block_aaaa_wdata to support custom local data fallback. o Management Improvements: Overloaded local_data_remove to allow the removal of precise records. o Fix for the Jiggle Attack. The server is fixed to answer with errors for error cases, and does not stay silent. In addition, the error replies do not contain parts of the incoming query. This is more conformant, stops reflection and stops it as a covert channel. o Fix EDNS extended RCODE reflection. This fixes that the server does not echo extended rcode values after class chaos queries. o Fix for iterator RCODE handling of YXDOMAIN. This fixes that the server only accepts YXDOMAIN answers that contain a DNAME record. This stops bad answers, and checks that the authoritative server gives correct replies. o Fix for missing bounds check for decompressing dnames for downloaded authority zones. This fixes that the server could end up with malformed zone content after receiving truncated packet contents from an AXFR. In addition, the domain names in the SOA rdata are checked before the authority code picks up the zone serial. o Fix that upstream TLS connections are not reused as TLS connections for a different name, at the same IP. This checks that the tls name is correct when reusing the upstream connections. o Fix that signatures are not allowed with revoked dnskeys. o Fix that a DNAME with an unsigned CNAME is checked for the correct match. This stops that for certain zone configurations an unchecked unsigned CNAME could get secure status. o Fix handling of wildcard CNAMEs in the chain of trust. An improper wildcard in the chain of trust would send the retries to the wrong upstream. Also it could label the step in the chain of trust as secure, when it was not. o Introduce new 'tls-protocols' configuration option that specifies which of the supported TLS protocols will be used. o Fix RFC7766 compliance when client sends EOF over TCP. It stops pending replies and closes. o Fix to shorten RRSIG count in scrubber, this protects against an overly large number of RRSIGs. It can be configured with `iter-scrub-rrsig: 8`, it has default 8. o Fix for EDNS client subnet so that it does not store SERVFAIL in the global cache after a failed lookup, such as timeouts. A failure entry is stored in the subnet cache, for the query name, for a couple of seconds. Queries can continue to use the subnet cache during that time. o Fix to allow the control-interface config to use ip@port notation. o Fix to check for invalid http content length and chunk size, and to check the RR rdata field lengths when decompressing and inserting RRs from an authority zone transfer. This stops large memory use and heap buffer-overflow read errors. o Fix to ignore out-of-zone DNAME records for CNAME synthesis. Fix so that a reload checks if the files have changed, and if so, reload the contexts. Also for DoH, DoQ and outgoing DoT. o Apply cache TTL policy to DNAME and synthesized CNAME on wire path. o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound. o Allow synthesized DNAME TTL=0 to be served from cache within grace period. The responses are served from cache within a 1-second grace period. Reduces recursion when authoritative servers return DNAME with TTL=0 (RFC 2308). Response still returns TTL=0 to clients. o On Linux systems log the system-wide unique thread ID instead of Unbound's internal thread counter. o Introduce the 'log-thread-id' configuration option to manage logging the system-wide Linux thread ID for easier debugging with system tools. o Mesh reply counters. This adds statistics num.queries.replyaddr_limit and requestlist.current.replies. o Add extra statistic to track the number of signature validation operations. Adds 'num.valops' to extended statistics. o Fix for cname chain length with qtype ANY and qname minimisation. o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where the UDP socket send buffers are exhausted waiting for ARP/NDP resolution. o Increase default to `num-queries-per-thread: 2048`, when unbound is compiled with libevent. It makes saturation of the task queue more resource intensive and less practical. o DNS Error Reporting (RFC 9567). Introduces new configuration option 'dns-error-reporting' and new statistics for 'num.dns_error_reports'. o Redis read-only replica support. Introduces new 'redis-replica-*' options for the Redis cache backend. o Exempt loopback addresses from wait-limit. o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse to allow two arguments. o Fast Reload. The unbound-control fast_reload is added. It reads changed config in a thread, then only briefly pauses the service threads, that keep running. DNS service is only interrupted briefly. o Make the default value of module-config "validator iterator" regardless of compilation options. --enable-subnet would implicitly change the value to enable the subnetcache module by default in the past. o Add unbound members group access to control key. o Add resolver.arpa and service.arpa to the default locally served zones. o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake. o Serve expired cache update fixes. Fixes a regression bug with serve-expired that appeared in 1.22.0 and would not allow the iterator to update the cache with not-yet-validated entries resulting in increased outgoing traffic. Closes: #1142539 o The default value of serve-expired-ttl is set to 86400 (1 day) as suggested by RFC8767. o Increase the default of max-global-quota to 200 from 128 after operational feedback. Still keeping the possible amplification factor (CAMP related issues) in the hundreds. o Fix for the serve expired DNSSEC information fix, it would not allow current delegation information be updated in cache. The fix allows current delegation and validation recursion information to be updated, but as a consequence no longer has certain expired information around for later dnssec valid expired responses. o Statistics for discard-timeout and wait-limit. . * Other packaging changes: - d/rules,d/libunbound-dev.install: drop static library and deps (Closes: #1096189) - unbound-helper: do not update resolvconf if it is systemd-resolved - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd - d/upstream/signing-key.asc: update with the new upstream key - d/unbound.conf.d/remote-control.conf: fix typo Checksums-Sha1: 0d094b9ba823143f80934a49b67a496c1cff17b2 213584 libunbound-dev_1.26.1-0+deb13u1_armhf.deb 31c22718f4cbfb1ce5a24d7a84a0750072e6372b 1388116 libunbound8-dbgsym_1.26.1-0+deb13u1_armhf.deb 2c96155d8969e1080aa73adc48f32914a38955e2 583024 libunbound8_1.26.1-0+deb13u1_armhf.deb 961bdff45f5a276de5bf73b4a99bd643c613978c 179996 python3-unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb 8957b58eaa21d7973a06145e4b98613a31f4f10c 243116 python3-unbound_1.26.1-0+deb13u1_armhf.deb f006d8192bb09355b5776099f9d272dc95599978 59684 unbound-anchor-dbgsym_1.26.1-0+deb13u1_armhf.deb 12d89089e10c3127e6a92a3ba62d6cc913623751 220212 unbound-anchor_1.26.1-0+deb13u1_armhf.deb 4b3359c95fc045b91d3426abbd134ebbba8d9959 5218228 unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb 2e78d9eacd4de54f3467d6324ea35a8ff3b534e5 132540 unbound-host-dbgsym_1.26.1-0+deb13u1_armhf.deb bee0d2226e95d9a3e54621c91723565daf23020c 235592 unbound-host_1.26.1-0+deb13u1_armhf.deb 4aeb55c78937b5f3682fbd0b7a0e555ed3ee3593 10463 unbound_1.26.1-0+deb13u1_armhf-buildd.buildinfo 03c537eb64d19b3d90dd18c397a458f4d62db2e6 975968 unbound_1.26.1-0+deb13u1_armhf.deb Checksums-Sha256: 763650efd2f2b91ee89ce316c0eebf47954cecd70d73179fc57cb09ba423be88 213584 libunbound-dev_1.26.1-0+deb13u1_armhf.deb 36a34680bdbe1c10c7054339c3cacdda7f88387908e246a6921375f0786b57b8 1388116 libunbound8-dbgsym_1.26.1-0+deb13u1_armhf.deb 7f02467cb508ba16a93c50036031a660962d74daa051ed405a2f668be8d73d85 583024 libunbound8_1.26.1-0+deb13u1_armhf.deb 38d5e49b959df45f9eae218442ccf8c5ba3982d43a92af9e7a803fb66ae71247 179996 python3-unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb acc25f238da8cf6361fbad16f02a25c1c0e6e2d9a2953aa717c17d7070e4ae46 243116 python3-unbound_1.26.1-0+deb13u1_armhf.deb 2345fd8803fbe36bb5cfb16e7656dfa20ac5cae88051e6d67a113c044a1351c2 59684 unbound-anchor-dbgsym_1.26.1-0+deb13u1_armhf.deb 69bf6d063c1064c1e988add686ef151fabbffc58f6862d4be36765078013c0a4 220212 unbound-anchor_1.26.1-0+deb13u1_armhf.deb b3fda0ff80e3703e288a7985a2b8a468cd19cfb0c7c75fd3bcdcc2aa49a9dfb6 5218228 unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb d9279fe2a5ccb563c93cc6c8bf4b1bd91871599edad44a6640c1a0e019435145 132540 unbound-host-dbgsym_1.26.1-0+deb13u1_armhf.deb aa917ada140d28b496b45ad4f3e88cd528b1ac1efc88fba3779270e9170a2790 235592 unbound-host_1.26.1-0+deb13u1_armhf.deb 536461ded8d82f5e8da66bf50b0f41cd092514bf65855d2882e66ce252dfd91d 10463 unbound_1.26.1-0+deb13u1_armhf-buildd.buildinfo 3394b06ec325348ea725293f72668ac999bf2ea84f1e41ab794394fafbc250ea 975968 unbound_1.26.1-0+deb13u1_armhf.deb Files: e50e055b9bde0bdfcf3f5a629314ab07 213584 libdevel optional libunbound-dev_1.26.1-0+deb13u1_armhf.deb d7cf2dc4f83ecf2406bcc21cc10615e2 1388116 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_armhf.deb f1ce7a6d36c027339313f7dd72f14dd2 583024 libs optional libunbound8_1.26.1-0+deb13u1_armhf.deb b06a8fb85924f9af55ccf1c7c03cd751 179996 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb 26e4292b05920f5f06bfbade071f9cc9 243116 python optional python3-unbound_1.26.1-0+deb13u1_armhf.deb be9882ffee7dc5ba63ff2bc0b32410e2 59684 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_armhf.deb 73328108ff12b7643882e7804c4ec58a 220212 net optional unbound-anchor_1.26.1-0+deb13u1_armhf.deb 38073ae623d807da4053d8bb4b777e81 5218228 debug optional unbound-dbgsym_1.26.1-0+deb13u1_armhf.deb 9fe8a8f458b0a337588297900af1a423 132540 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_armhf.deb 34cce4e0b993365127f4d93342b717d1 235592 net optional unbound-host_1.26.1-0+deb13u1_armhf.deb e43053a52b8f524d2262de486843e5f7 10463 net optional unbound_1.26.1-0+deb13u1_armhf-buildd.buildinfo 2821af1581a7294aeee51f43c06afb83 975968 net optional unbound_1.26.1-0+deb13u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmqtZ4cACgkQutMAkCxK bL3QqBAAr24fmDxjyuz2MGlW8+0ShqT0ndJ+EMxq6jVUvII34wSEdHFfUl56gvub eDTrI2ttWKa5AoBPVIzUi/UfVk9Os3wdEfjgrJ3vs80j+H64yFLq5LGpN+vesCZO 0HUpJ5JxqCPZgWtHw5cOrQ53H4Ia9UyypfuRiumEtPWrSgS0/r1eo978C7wwO0f5 4GT28ZHa70Kux39eJZ0i88j9zTG/ba6h+c9zscaI3eb7QoWNkPWHd1SQpOfLcXVV MFlo9tPstXccdi9M3uTYc1utIXG3pUGI7tcLF/gFc1rfNYFhuFkeJ158cyKkxp6s GOFN9kQR0C21fhDm7teoRl8irLkaCAGycRbm4TzrdsnthdtJJo9kQXEkpNnPB+Id 5VoLfNJ2H/SnDhYevWwGPWEr+PQA31Cd54wLD5aFj4Fl8OQ1GkTvesSipRy74hpE ReJaHCZYvj7ZHT+iMFbXxPs6aBo2if92hD6aXBUo4x28MxX+nnNX0G1f8KV0r+SD CeQzybsma0igI3qtPufI+goNQxcc81dR1M2r3paNuGy8qP9lqtsvheHTZvDW8Mfc udmtg0IFGKVseqrHMdVCwsOunxbK1nm9aoHvrGCh7j2B7rU6JL+3jzv6/CkVs+TI r2FAQfa1lIPodrfCDYWhmnxJlC1islvMb77M4E/o/AsLOVXXewc= =7w+p -----END PGP SIGNATURE-----