Debian Package Tracker
Register | Log in
Subscribe

knot

Authoritative DNS server

Choose email to subscribe with

general
  • source: knot (main)
  • version: 3.5.6-1
  • maintainer: knot packagers (DMD)
  • uploaders: Daniel Kahn Gillmor [DMD] – Robert Edmonds [DMD] – Daniel Salzman [DMD] – Jakub Ružička [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.0.5-1+deb11u1
  • oldstable: 3.2.6-1
  • stable: 3.4.6-2
  • testing: 3.5.6-1
  • unstable: 3.5.6-1
versioned links
  • 3.0.5-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.6-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.5.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • knot
  • knot-dnssecutils
  • knot-dnsutils
  • knot-doc
  • knot-exporter
  • knot-host
  • knot-keymgr
  • knot-module-dnstap
  • knot-module-geoip
  • libdnssec10
  • libknot-dev
  • libknot16
  • libzscanner5
  • python3-libknot
  • redis-module-knot
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-39155: Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
Created: 2026-07-25 Last update: 2026-08-01 20:32
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-23 Last update: 2026-04-24 10:01
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2026-39155: (postponed; to be fixed through a stable update) Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-07-25 Last update: 2026-08-01 20:32
news
[rss feed]
  • [2026-07-29] knot 3.5.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-24] Accepted knot 3.5.6-1 (source) into unstable (Simon Josefsson)
  • [2026-07-05] knot 3.5.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-03] Accepted knot 3.5.5-1 (source) into unstable (Simon Josefsson)
  • [2026-04-25] knot 3.5.4-2 MIGRATED to testing (Debian testing watch)
  • [2026-04-22] Accepted knot 3.5.4-2 (source) into unstable (Santiago Ruano Rincón)
  • [2026-04-10] knot 3.5.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-07] Accepted knot 3.5.4-1 (source) into unstable (Santiago Ruano Rincón)
  • [2026-04-07] knot 3.5.3-3 MIGRATED to testing (Debian testing watch)
  • [2026-04-04] Accepted knot 3.5.3-3 (source) into unstable (Santiago Ruano Rincón)
  • [2026-02-20] knot 3.5.3-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-16] Accepted knot 3.5.3-2 (source) into unstable (Santiago Ruano Rincón)
  • [2026-01-24] knot 3.5.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-20] Accepted knot 3.5.3-1 (source) into unstable (Santiago Ruano Rincón)
  • [2025-12-05] knot 3.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-02] Accepted knot 3.5.2-1 (source) into unstable (Jakub Ružička)
  • [2025-10-20] knot 3.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-17] Accepted knot 3.5.1-1 (source) into unstable (Jakub Ružička)
  • [2025-10-04] knot 3.5.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-04] knot 3.5.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-09-30] Accepted knot 3.5.0-2 (source) into unstable (Jakub Ružička)
  • [2025-09-30] Accepted knot 3.5.0-1 (source amd64 all) into unstable (Debian FTP Masters) (signed by: Jakub Ružička)
  • [2025-07-30] Accepted knot 3.4.8-1 (source) into experimental (Jakub Ružička)
  • [2025-07-14] Accepted knot 3.4.7-1 (source) into experimental (Jakub Ružička)
  • [2025-05-13] knot 3.4.6-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-02] Accepted knot 3.4.6-2 (source) into unstable (Jakub Ružička)
  • [2025-04-12] knot 3.4.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-10] Accepted knot 3.4.6-1 (source) into unstable (Jakub Ružička)
  • [2025-03-22] knot 3.4.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-19] Accepted knot 3.4.5-1 (source) into unstable (Jakub Ružička)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.5.4-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing