-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 17 Sep 2026 11:55:59 +0300
Source: unbound
Binary: libunbound-dev libunbound8 libunbound8-dbgsym python3-unbound python3-unbound-dbgsym unbound unbound-anchor unbound-anchor-dbgsym unbound-dbgsym unbound-host unbound-host-dbgsym
Architecture: armel
Version: 1.26.1-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: armel Build Daemon (arm-conova-01) <buildd_arm64-arm-conova-01@buildd.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Description:
 libunbound-dev - static library, header files, and docs for libunbound
 libunbound8 - library implementing DNS resolution and validation
 python3-unbound - library implementing DNS resolution and validation (Python3 bindi
 unbound    - validating, recursive, caching DNS resolver
 unbound-anchor - utility to securely fetch the root DNS trust anchor
 unbound-host - reimplementation of the 'host' command
Closes: 1096189 1142539
Changes:
 unbound (1.26.1-0+deb13u1) trixie-security; urgency=medium
 .
   * New upstream release fixing numerous security and other issues and contains
     some enhancements.
 .
     Traditionally in Debian, bugs in stable versions are fixed by providing
     a back-port of a fix from later upstream version to the version in Debian
     stable.  With unbound, fixes in subsequent versions can not be applied
     directly to the version in Debian stable, as there were multiple other code
     changes in these areas.  Many of these changes fixes other issues (security
     or not).  Some changes are in areas with complex logic, hence requires
     creat care when back-porting to older releases.  And the result of such
     back-porting becomes unique and rather unpredictable.  So instead of trying
     to provide fixes for older version in Debian stable, we decided to provide
     current upstream version of unbound, - the same as currently available in
     Debian Sid.  The packaging is made very similar too.
 .
     Recent security fixes:
 .
     o CVE-2026-81642 - severity: CRITICAL
       Heap buffer overflow and possible Remote Code Execution
       when digesting DNSKEY
     o CVE-2026-81634 - severity: HIGH
       Possible heap buffer overflow during DNSSEC canonicalization
     o CVE-2026-82717 - severity: HIGH
       CNAME synthesis could lead to heap corruption
     o CVE-2026-77955 - severity: MEDIUM
       Possible ZONEMD verification bypass window
     o CVE-2026-78227 - severity: MEDIUM
       Use-after-free in DoQ stream output buffer on reset re-transmission
     o CVE-2026-80225 - severity: MEDIUM
       Possible degradation of service from continuous queries
       on the same TCP/DoT connection
     o CVE-2026-82720 - severity: MEDIUM
       Use-after-free in DoH stream cleanup code path
     o CVE-2026-85501 - severity: MEDIUM
       Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks
       on DNSSEC
     o CVE-2026-77860 - severity: LOW
       'serve-expired' can bypass Unbound 'wait-limit'
     o CVE-2026-32665 - severity: HIGH
       Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
     o CVE-2026-40691 - severity: HIGH
       Packet of death for DNSCrypt over TCP
     o CVE-2026-44690 - severity: HIGH
       Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
     o CVE-2026-55973 - severity: HIGH
       'dns-error-reporting: yes' leads to stack buffer overflow
     o CVE-2026-14586 - severity: MEDIUM
       Assertion in libngtcp2 when under pressure in high concurrency
       DNS-over-QUIC environments
     o CVE-2026-44621 - severity: MEDIUM
       Libunbound applications configured with 'unwanted-reply-threshold'
       could eventually be abruptly terminated
     o CVE-2026-50045 - severity: MEDIUM
       'max-global-quota' reset by DNSSEC validation restarts
     o CVE-2026-50046 - severity: MEDIUM
       Possible heap use-after-free in an error path when
       a DoT forwarded query is jostled out
     o CVE-2026-50243 - severity: MEDIUM
       response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL
     o CVE-2026-50248 - severity: MEDIUM
       BOGUS configured primary hostname accepted for XFR in auth/rpz zones
     o CVE-2026-50251 - severity: MEDIUM
       Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush
     o CVE-2026-50252 - severity: MEDIUM
       Possible cache poisoning attack by mapping source port population
       per thread
     o CVE-2026-52863 - severity: MEDIUM
       Memory corruption could lead to crash and denial of service
     o CVE-2026-55717 - severity: MEDIUM
       'serve-expired-client-timeout' and 'response-ip' CNAME redirect
       could lead to a crash
     o CVE-2026-55990 - severity: MEDIUM
       Packet of death for a DNSCrypt misconfigured Unbound
     o CVE-2026-55991 - severity: MEDIUM
       Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
     o CVE-2026-56416 - severity: MEDIUM
       Possible heap buffer overflow when validator canonicalizes RDATA
       that contains domain name
     o CVE-2026-56444 - severity: MEDIUM
       Degradation of resolution service when 'discard-timeout' and
       'serve-expired-client-timeout' are combined in unusual configuration
     o CVE-2026-41637 - severity: LOW
       Degradation of resolution service from improperly accounted
       client-terminated DNS-over-QUIC queries
     o CVE-2026-42955 - severity: LOW
       Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records
       disallowing a one-time 'ghost domain' delegation renewal via glue records
     o CVE-2026-44687 - severity: LOW
       Off-by-one error in 'harden-below-nxdomain' logic can shadow
       a stub/forward zone by a legitimate parent's NXDOMAIN
     o CVE-2026-46582 - severity: LOW
       A wildcard replay, as another piece of data, triggers poisoning
       in the serve expired reply path
     o CVE-2026-54478 - severity: LOW
       DNS Cookie bypass when combined with proxy-protocol use
     o CVE-2026-55708 - severity: LOW
       Privacy/configuration issue when adding local data in views
       through 'unbound-control'
 .
     Other notable user-visible changes and fixes.  For complete list, please
     see /usr/share/doc/unbound/changelog.gz
 .
     o ICANN Bundle Update: Refreshed icannbundle.pem certificates in
       unbound-anchor to include public keys valid for 2009–2029 and 2025–2045
     o Transfer Limits: Added max-transfer-size and max-transfer-time directives
       to limit authorization zone (auth-zone) and RPZ transfer sizes and times
       to harden against unbounded transfers.
     o New Zone Types: Introduced block_aaaa static zone type to suppress AAAA
       queries, plus block_a_wdata and block_aaaa_wdata to support custom local
       data fallback.
     o Management Improvements: Overloaded local_data_remove
       to allow the removal of precise records.
     o Fix for the Jiggle Attack. The server is fixed to answer with errors
       for error cases, and does not stay silent.  In addition, the error
       replies do not contain parts of the incoming query.  This is more
       conformant, stops reflection and stops it as a covert channel.
     o Fix EDNS extended RCODE reflection. This fixes that the server does not
       echo extended rcode values after class chaos queries.
     o Fix for iterator RCODE handling of YXDOMAIN.  This fixes that the server
       only accepts YXDOMAIN answers that contain a DNAME record.  This stops
       bad answers, and checks that the authoritative server gives correct
       replies.
     o Fix for missing bounds check for decompressing dnames for downloaded
       authority zones.  This fixes that the server could end up with malformed
       zone content after receiving truncated packet contents from an AXFR.
       In addition, the domain names in the SOA rdata are checked before the
       authority code picks up the zone serial.
     o Fix that upstream TLS connections are not reused as TLS connections for
       a different name, at the same IP.  This checks that the tls name is
       correct when reusing the upstream connections.
     o Fix that signatures are not allowed with revoked dnskeys.
     o Fix that a DNAME with an unsigned CNAME is checked for the correct match.
       This stops that for certain zone configurations an unchecked unsigned
       CNAME could get secure status.
     o Fix handling of wildcard CNAMEs in the chain of trust.  An improper
       wildcard in the chain of trust would send the retries to the wrong
       upstream.  Also it could label the step in the chain of trust as secure,
       when it was not.
     o Introduce new 'tls-protocols' configuration option that specifies which
       of the supported TLS protocols will be used.
     o Fix RFC7766 compliance when client sends EOF over TCP.
       It stops pending replies and closes.
     o Fix to shorten RRSIG count in scrubber, this protects against an overly
       large number of RRSIGs.  It can be configured with `iter-scrub-rrsig: 8`,
       it has default 8.
     o Fix for EDNS client subnet so that it does not store SERVFAIL in the
       global cache after a failed lookup, such as timeouts.  A failure entry is
       stored in the subnet cache, for the query name, for a couple of seconds.
       Queries can continue to use the subnet cache during that time.
     o Fix to allow the control-interface config to use ip@port notation.
     o Fix to check for invalid http content length and chunk size, and to check
       the RR rdata field lengths when decompressing and inserting RRs from
       an authority zone transfer.  This stops large memory use and heap
       buffer-overflow read errors.
     o Fix to ignore out-of-zone DNAME records for CNAME synthesis.
       Fix so that a reload checks if the files have changed, and if so, reload
       the contexts.  Also for DoH, DoQ and outgoing DoT.
     o Apply cache TTL policy to DNAME and synthesized CNAME on wire path.
     o Fix for DNS Rebinding Bypass via SVCB/HTTPS Records in Unbound.
     o Allow synthesized DNAME TTL=0 to be served from cache within grace
       period.  The responses are served from cache within a 1-second grace
       period.  Reduces recursion when authoritative servers return DNAME with
       TTL=0 (RFC 2308).  Response still returns TTL=0 to clients.
     o On Linux systems log the system-wide unique thread ID instead of
       Unbound's internal thread counter.
     o Introduce the 'log-thread-id' configuration option to manage logging the
       system-wide Linux thread ID for easier debugging with system tools.
     o Mesh reply counters.  This adds statistics num.queries.replyaddr_limit
       and requestlist.current.replies.
     o Add extra statistic to track the number of signature validation
       operations.  Adds 'num.valops' to extended statistics.
     o Fix for cname chain length with qtype ANY and qname minimisation.
     o Change default for so-sndbuf to 4m, to mitigate a cross-layer issue where
       the UDP socket send buffers are exhausted waiting for ARP/NDP resolution.
     o Increase default to `num-queries-per-thread: 2048`, when unbound is
       compiled with libevent.  It makes saturation of the task queue more
       resource intensive and less practical.
     o DNS Error Reporting (RFC 9567).  Introduces new configuration option
       'dns-error-reporting' and new statistics for 'num.dns_error_reports'.
     o Redis read-only replica support.  Introduces new 'redis-replica-*'
       options for the Redis cache backend.
     o Exempt loopback addresses from wait-limit.
     o Fix wait-limit-netblock and wait-limit-cookie-netblock config parse
       to allow two arguments.
     o Fast Reload.  The unbound-control fast_reload is added.  It reads
       changed config in a thread, then only briefly pauses the service threads,
       that keep running.  DNS service is only interrupted briefly.
     o Make the default value of module-config "validator iterator" regardless
       of compilation options.  --enable-subnet would implicitly change the
       value to enable the subnetcache module by default in the past.
     o Add unbound members group access to control key.
     o Add resolver.arpa and service.arpa to the default locally served zones.
     o Use TCP_NODELAY on TLS sockets to speed up the TLS handshake.
     o Serve expired cache update fixes.  Fixes a regression bug with
       serve-expired that appeared in 1.22.0 and would not allow the iterator
       to update the cache with not-yet-validated entries resulting in increased
       outgoing traffic.  Closes: #1142539
     o The default value of serve-expired-ttl is set to 86400 (1 day)
       as suggested by RFC8767.
     o Increase the default of max-global-quota to 200 from 128 after
       operational feedback.  Still keeping the possible amplification factor
       (CAMP related issues) in the hundreds.
     o Fix for the serve expired DNSSEC information fix, it would not allow
       current delegation information be updated in cache.  The fix allows
       current delegation and validation recursion information to be updated,
       but as a consequence no longer has certain expired information around
       for later dnssec valid expired responses.
     o Statistics for discard-timeout and wait-limit.
 .
   * Other packaging changes:
    - d/rules,d/libunbound-dev.install: drop static library and deps
      (Closes: #1096189)
    - unbound-helper: do not update resolvconf if it is systemd-resolved
    - d/unbound.service: set empty DAEMON_OPTS= to avoid warning from systemd
    - d/upstream/signing-key.asc: update with the new upstream key
    - d/unbound.conf.d/remote-control.conf: fix typo
Checksums-Sha1:
 32bfa69113eef588877a8dc3ade661b786d80522 213576 libunbound-dev_1.26.1-0+deb13u1_armel.deb
 b750255844655ae4ad8bf6cef5fbbf3e0bb774b0 1370416 libunbound8-dbgsym_1.26.1-0+deb13u1_armel.deb
 eaf095e533886bd45978b0491da2a5f9f2e5290c 575716 libunbound8_1.26.1-0+deb13u1_armel.deb
 1382700a660d92ea18db58eb85bc8b92abb9db00 179272 python3-unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 712158342159b2579df85596ea328efd97b40295 242176 python3-unbound_1.26.1-0+deb13u1_armel.deb
 6ce7487dcb0610d46e4c1ef056c8fd11cb392801 58904 unbound-anchor-dbgsym_1.26.1-0+deb13u1_armel.deb
 5d952916ec8c146deb9201d8f94def8aa3b28e1f 220024 unbound-anchor_1.26.1-0+deb13u1_armel.deb
 546fe8c97f3aff92847c4ccc9c49c0d4e90fc91d 5122308 unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 09f0e02f82cca29ef417d9ccdb589720631b302c 131720 unbound-host-dbgsym_1.26.1-0+deb13u1_armel.deb
 4e3fa10b132e7ad332f449b7154859cd2c975c4d 237440 unbound-host_1.26.1-0+deb13u1_armel.deb
 53ffaf23adbd58a7c09b9d5dac2bfd5e4864c2d4 10449 unbound_1.26.1-0+deb13u1_armel-buildd.buildinfo
 299871cc3086f9c8240654d2a25281abc1a0b238 971988 unbound_1.26.1-0+deb13u1_armel.deb
Checksums-Sha256:
 39c5205f8286b6cd4c4ed97ad2582a940d9ff9b3dd1ce3edb03036bbed57de78 213576 libunbound-dev_1.26.1-0+deb13u1_armel.deb
 be9c95cb80225db106ee81b61ef6eb09651fc928e37b065a829bb7bb49318ccf 1370416 libunbound8-dbgsym_1.26.1-0+deb13u1_armel.deb
 5230d804abfbc3d93f3ee1833d3300047cf04a2b4197fe8f54fe94aec148b2ce 575716 libunbound8_1.26.1-0+deb13u1_armel.deb
 a0077fa9bd835b4b769cd4ded2c77d41f66eb74cd4f138631dfff0b3623d4e6f 179272 python3-unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 be5b5170426bf590881eeaf002cce416b416a5262f70703559a0e8436f58dfa3 242176 python3-unbound_1.26.1-0+deb13u1_armel.deb
 d1f5b6c46e0532efdac91aa460381461d9378a77487f6ee477a97c5af0e2d6d0 58904 unbound-anchor-dbgsym_1.26.1-0+deb13u1_armel.deb
 22695bd57ad3179e6d8397e9cd94260fa24cd8bf14ad84a4e747a73a77737117 220024 unbound-anchor_1.26.1-0+deb13u1_armel.deb
 27f78722e916e05571cd16b657f7b4f898d40c15ac820131feb009e9f68dd121 5122308 unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 107b6a94bb642195f5e41948fc1ad0646e9765bfe18d5191f59c76b33d120b44 131720 unbound-host-dbgsym_1.26.1-0+deb13u1_armel.deb
 c6b14552452e6b35a952a5e3e554100c748153c248576a89575440cdd8e0eddb 237440 unbound-host_1.26.1-0+deb13u1_armel.deb
 03cc68b920941daac5fada285dda12a8bdfda342eff0ec77da32089cae445103 10449 unbound_1.26.1-0+deb13u1_armel-buildd.buildinfo
 a9bb499ff9c12d28a7b0eceeeed49b1cc8a4d00b8b3394b2401cb2d3384f19c0 971988 unbound_1.26.1-0+deb13u1_armel.deb
Files:
 9234da9e1ddac48d2c0449876bf1a66c 213576 libdevel optional libunbound-dev_1.26.1-0+deb13u1_armel.deb
 0593c3e6ab90db4443c4ad216ff000ad 1370416 debug optional libunbound8-dbgsym_1.26.1-0+deb13u1_armel.deb
 cb149e81d695e91d49d940691c0e0edc 575716 libs optional libunbound8_1.26.1-0+deb13u1_armel.deb
 a6dd1ebfda1a2a8cbaf7e0720ddddb1d 179272 debug optional python3-unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 1f2564f7649234280bf5c6358d33f960 242176 python optional python3-unbound_1.26.1-0+deb13u1_armel.deb
 ee9e68d55cc18d328268b680b4723cb1 58904 debug optional unbound-anchor-dbgsym_1.26.1-0+deb13u1_armel.deb
 3e2a0a750ba01fcb7168ab424a80b329 220024 net optional unbound-anchor_1.26.1-0+deb13u1_armel.deb
 cc9a3e7c1f7e0348beb0a78bbc0b06e4 5122308 debug optional unbound-dbgsym_1.26.1-0+deb13u1_armel.deb
 566e4606ab7ab434695287b94112c2bd 131720 debug optional unbound-host-dbgsym_1.26.1-0+deb13u1_armel.deb
 ff36b1244db3d62b999030f73f5a7438 237440 net optional unbound-host_1.26.1-0+deb13u1_armel.deb
 e69057499bfb103ef6519635c93b228d 10449 net optional unbound_1.26.1-0+deb13u1_armel-buildd.buildinfo
 fb94cc7fdb64748dbb86137939895dcb 971988 net optional unbound_1.26.1-0+deb13u1_armel.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEO4qAQUSIo2p/kVRf8U6eOZMpj68FAmqtZ3YACgkQ8U6eOZMp
j68wBxAAg8KjJfXnrWWs9ab+wyF3bQfLdAtR3VgJYSrSzDVm1dQRGE0SZR1E6oJS
yvrzV21BuSHODG3BuzEwVQixTWt9qriG7MKJcw7l9+m++Lh1Q16niwhsuoxncQU+
nxZg4cdooRXNYo/yCbKDvjCwjplovYOKL/jyurDY3cSLXvdLparEv7KuhtasXzEw
+w6rezNelO++vgCMAO8Zur840Y5wIA0V/FpyvCkoJNotMlEMiiOZNMc+FRjcdsnu
oB3eRyWs3qBVEjnmAu8Etb5SvEmvMz43B6qiJA+8n/cmGUTE1h+RE1vZXYl/v8iV
1bAzTPrkzoDMuIQDnGm5rB3Y2lhEwQMpDhiUa11ckc92HKr/wKl1gJzHFEplVsJi
c4Gaa2bcksCKsaXCFQI/7u+Xjf8FZpRPB/w4c467b4z0o87TkWfpZXSb5I5ukTsZ
Ui64NQS/5NG1QgwLWNT8tSdNfHTtpZstBcrqpWlyO7HM+5L9uKJH2YWWMOELbns/
nhEDy1UXuSnPiQ4s3ymtp50eY6hBLsxqNgwLTk00wRHzWdSJOwH+4+mXv1NdZHpR
2Z/0tnL0v3ESyvkoo7/OTyCvS8PZRR7TRawZI00xFNIW5/1q3SfIBvBlQMqBk5Vh
RcNZz2K3sw6ySa/FfNvALsjRs+Mzv70wtIMd5bxhNJNtAdXa+Vw=
=AiDy
-----END PGP SIGNATURE-----
