-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 20 May 2026 19:41:23 +0300 Source: unbound Architecture: source Version: 1.25.1-1 Distribution: unstable Urgency: medium Maintainer: unbound packagers <unbound@packages.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Closes: 1137187 Changes: unbound (1.25.1-1) unstable; urgency=medium . * new upstream security/bugfix release (Closes: #1137187): - Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation - Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options - Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content - Fix CVE-2026-32792, Packet of death with DNSCrypt - Fix CVE-2026-40622, "Ghost domain name" variant - Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance - Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance - Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations - Fix CVE-2026-42960, Possible cache poisoning attack while following delegation - Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service - Fix CVE-2026-44608, Use after free and crash in RPZ code Checksums-Sha1: d39ec195ff06f4af88ab73f6f91b62439a860d84 3319 unbound_1.25.1-1.dsc 382e12658a8c8e63ffb3edb1c6592b54a7a75ce3 6832247 unbound_1.25.1.orig.tar.gz 723ef826f6edc754243860023b4c8de79d878dd8 659 unbound_1.25.1.orig.tar.gz.asc f0551a63b60164e777c71fc7ee5b183cba1cc87f 28460 unbound_1.25.1-1.debian.tar.xz 579409b2cb9756478949c1bd9e9634d0c828b4be 6971 unbound_1.25.1-1_source.buildinfo Checksums-Sha256: 7d643c0e718c2c505d643b5f95685c16b115ad8185a1ee206292f3b3b35b5dde 3319 unbound_1.25.1-1.dsc 0fe8b6277b0959cfd17562debac0aa5f71e0b02dc4ffa9c60271c583edab586f 6832247 unbound_1.25.1.orig.tar.gz 387296d9a53d59fef89b5ccc3be7a58306fcb3c5febf1e99270ccca9030127a1 659 unbound_1.25.1.orig.tar.gz.asc 2e4fc847b61f48ae463a72301f7c47089e39b8f5d0584abe8a2fb3e07e0c335e 28460 unbound_1.25.1-1.debian.tar.xz bbcd9c79db7e92a714efad8326d10c2e5067da95974b3f868a6b14bccd91f79c 6971 unbound_1.25.1-1_source.buildinfo Files: 2d8342d02766ad425da48612e412e5c5 3319 net optional unbound_1.25.1-1.dsc dce631cc8c882ebc707dade27e7fe6f3 6832247 net optional unbound_1.25.1.orig.tar.gz 43b4636405a776623f1dd2dedd1e7f2e 659 net optional unbound_1.25.1.orig.tar.gz.asc 087760f8687b331569088b50877bc8d5 28460 net optional unbound_1.25.1-1.debian.tar.xz 21cb9d25a2a7b594d44cc6ce8fded7b6 6971 net optional unbound_1.25.1-1_source.buildinfo -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJqDeUtCRCCqkokOx6UeEcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmePh3SAz1INTohMpSCGYgpPXmvPzTPGNr3QaQM805Cf hxYhBGSqKrUx1WkDNmv++YKqSiQ7HpR4AAANExAAgRfkC0V27iuSlMnDh4lxkQoW OGdQh3uSBIw49dTuDPgwFScktGO/ACMudhgMz8xxLnemTJMuwiLwzMgJ4Hbtv2Sx yPMGkTs0qsD2xsGTMhCZkfPnDGmVDx7nXGJev2DvDMczHDm6ZDj0itKTi4n3b8OQ 3JNl6gSsiQ1XFTWb09Psq2hnJive6mfxhfwz2n748LJYKK438TKLxlQDkuggL9IY SDOpPzwP1MzsC0auiT0FDiMITz/EYseZCe23iUhBrjqwr8PTP3AFVE2cxLe8DJyi BXuqCJ7HxZsWJ/PsdYsFch4BoeJgbHqRx8KU22P9/eeMo1lNYeQpE4+2mPmYP8lI rrN6s8b+x6ZSk2YCS6wN2vNgL+oI3rGvzKkwLsz43L8ggmFL77Kri0GRvp9JpLGb uZshna4meL0fK9gunkNLjST4YcqKppI4CRsFlnB/Yi7qadBxKh/9B2j3HtE5ID46 q9jtShaDYaoN1c5gRsCZw/ys3wZCdN8d2c9EuJp/CY69UrRebc6cpyF9ed9G/pf7 C44Ir3UOrtfKdNZaWUi6cH6Ku5kjUBLsxtoRMnuvPt1Y2Zy9o1VUa0VR3Moa77UZ 9ZAu645ziUSB8GD0JMq4X8RkGpP0ZHqq4Nbwmx8LnJxdAw9xpTZNMVuNgtjoGgsW C0NbnQ1dCoahwjgTlrA= =QYg+ -----END PGP SIGNATURE-----