-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 22 Jul 2026 22:13:25 +0300
Source: unbound
Architecture: source
Version: 1.25.2-1
Distribution: unstable
Urgency: medium
Maintainer: unbound packagers <unbound@packages.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Changes:
unbound (1.25.2-1) unstable; urgency=medium
.
* new upstream release addressing the following vulnerabilities:
o CVE-2026-32665 - severity: HIGH
Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
o CVE-2026-40691 - severity: HIGH
Packet of death for DNSCrypt over TCP
o CVE-2026-44690 - severity: HIGH
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
o CVE-2026-55973 - severity: HIGH
'dns-error-reporting: yes' leads to stack buffer overflow
o CVE-2026-14586 - severity: MEDIUM
Assertion in libngtcp2 when under pressure in high concurrency
DNS-over-QUIC environments
o CVE-2026-44621 - severity: MEDIUM
Libunbound applications configured with 'unwanted-reply-threshold'
could eventually be abruptly terminated
o CVE-2026-50045 - severity: MEDIUM
'max-global-quota' reset by DNSSEC validation restarts
o CVE-2026-50046 - severity: MEDIUM
Possible heap use-after-free in an error path when
a DoT forwarded query is jostled out
o CVE-2026-50243 - severity: MEDIUM
response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL
o CVE-2026-50248 - severity: MEDIUM
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
o CVE-2026-50251 - severity: MEDIUM
Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush
o CVE-2026-50252 - severity: MEDIUM
Possible cache poisoning attack by mapping source port population
per thread
o CVE-2026-52863 - severity: MEDIUM
Memory corruption could lead to crash and denial of service
o CVE-2026-55717 - severity: MEDIUM
'serve-expired-client-timeout' and 'response-ip' CNAME redirect
could lead to a crash
o CVE-2026-55990 - severity: MEDIUM
Packet of death for a DNSCrypt misconfigured Unbound
o CVE-2026-55991 - severity: MEDIUM
Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
o CVE-2026-56416 - severity: MEDIUM
Possible heap buffer overflow when validator canonicalizes RDATA
that contains domain name
o CVE-2026-56444 - severity: MEDIUM
Degradation of resolution service when 'discard-timeout' and
'serve-expired-client-timeout' are combined in unusual configuration
o CVE-2026-41637 - severity: LOW
Degradation of resolution service from improperly accounted
client-terminated DNS-over-QUIC queries
o CVE-2026-42955 - severity: LOW
Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records
disallowing a one-time 'ghost domain' delegation renewal via glue records
o CVE-2026-44687 - severity: LOW
Off-by-one error in 'harden-below-nxdomain' logic can shadow
a stub/forward zone by a legitimate parent's NXDOMAIN
o CVE-2026-46582 - severity: LOW
A wildcard replay, as another piece of data, triggers poisoning
in the serve expired reply path
o CVE-2026-54478 - severity: LOW
DNS Cookie bypass when combined with proxy-protocol use
o CVE-2026-55708 - severity: LOW
Privacy/configuration issue when adding local data in views
through 'unbound-control'
Checksums-Sha1:
4db0de4bde3f40b28996c3186813c117ee69ebc4 3221 unbound_1.25.2-1.dsc
85db27eb1c2aca2f44f0fce117897649080a26c0 6839073 unbound_1.25.2.orig.tar.gz
d7d0f2c8a728224f4e62dfe1c63d943c4233a368 659 unbound_1.25.2.orig.tar.gz.asc
5b1a27e796999098e6702b65a44f2db332ac9514 29412 unbound_1.25.2-1.debian.tar.xz
14e51156c90b57cc02abf0c06c87cdb634954099 5684 unbound_1.25.2-1_source.buildinfo
Checksums-Sha256:
1cae0d2c1e4700c0db5f26a0bf2bc9181bd3e8d85f6e12c050df78d22022d8b2 3221 unbound_1.25.2-1.dsc
0d92275c703d5f5f8baba3dab22117dd8c29b495588a5c229768ed6581566600 6839073 unbound_1.25.2.orig.tar.gz
1348f018bb316a32dec586b9cf0ad831a8817cc5100479304d5ad8b6436ddd79 659 unbound_1.25.2.orig.tar.gz.asc
83db799d231965eb78edc035e5432752e6c7f3ebbf3adaf12d8fb225632c5672 29412 unbound_1.25.2-1.debian.tar.xz
82091a4954f4de0212da22c85f28866e2ccdceeef66acd7be5ffe12f3c48f1b8 5684 unbound_1.25.2-1_source.buildinfo
Files:
606ab78ca6b9644f2c423fc0f5791169 3221 net optional unbound_1.25.2-1.dsc
e387641957ace96c83c9e150c124b449 6839073 net optional unbound_1.25.2.orig.tar.gz
d2ef36c85468936cd8879b42e7e6353c 659 net optional unbound_1.25.2.orig.tar.gz.asc
e78d290510f67c3241b96697c650ffff 29412 net optional unbound_1.25.2-1.debian.tar.xz
947ddd2067a6dfc0c24fb9f5ddf688f5 5684 net optional unbound_1.25.2-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmphFp4ACgkQgqpKJDse
lHiC5Q//ZCY4oBsBAEUlBciblzWHPZ/TXCB5ncR3g7l9cZLIFll9CV0bKbotXzUz
cadFb3WTnADMW+zeeeTnkBPOLGYZFKuMqig48RFirjtvPW+drHMXFZCSrVnq2DWj
HDYsqThQ5JmArft7XsztR5FJ9MWZ8g8BynpsniknKunjpdVGhWsAqI36y5wyZxn1
UV+tL6+jCFCLywQQADE+JHDhvJS9XLKntUWcibvAoO/Q721ugMPnRoW6kD6YOvtx
AnNPwpDI1cOrT2DqmEOTaKrcfi2IfAtxnC21NH5V6qBzrNFXU58KtSl9nbvry+JQ
ax6F2TQdgekeM/BcXGssKl3Wfd+jjefXrK6upfVRYFeKOP1p4J3H4B/Y7rmwMSVx
YO7RgGuWFDe4kIY3I+OL2KWS+2pV/5+hZaKnFh90SxsTaa27qY7uIbuP7QSCNkgP
mWv7cRCbT//dhqo7lZxh475YPeBnOwp2EbbNy34f5e6ShmHhmyXjIgQYifigbRbr
CWPn+OXmTACd+sPVgBAaC6J1yw00Z75ZVA37dzKAo53bqiPmFHGHoUWc2VGo5sco
fccPFNuwbFxTpRKKxXB6A9yCNpSvnD2nC0sB1aa3ZwVYzQAMfgZwjyvbrQeUP1av
aQv+0rm8xj2aFZuSQnUGnW5OSTdfv8YJvjDYERXWNpaaVhF2oVA=
=yP8S
-----END PGP SIGNATURE-----