Debian Package Tracker
Register | Log in
Subscribe

ldns

Choose email to subscribe with

general
  • source: ldns (main)
  • version: 1.9.2-1
  • maintainer: Debian DNS Team (DMD)
  • uploaders: Ondřej Surý [DMD] – Daniel Kahn Gillmor [DMD] – Michael Tokarev [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7.1-2
  • oldstable: 1.8.3-1
  • stable: 1.8.4-2
  • testing: 1.9.0-1
  • unstable: 1.9.2-1
versioned links
  • 1.7.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ldnsutils (7 bugs: 0, 3, 4, 0)
  • libldns-dev
  • libldns3t64
  • python3-ldns
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-10846: NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
Created: 2026-06-10 Last update: 2026-06-14 19:00
3 security issues in bullseye high

There are 3 open security issues in bullseye.

1 important issue:
  • CVE-2026-10846: NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
2 issues postponed or untriaged:
  • CVE-2020-19860: (needs triaging) When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
  • CVE-2020-19861: (needs triaging) When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.
Created: 2026-06-10 Last update: 2026-06-14 19:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-10846: NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
Created: 2026-06-10 Last update: 2026-06-14 19:00
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-06-14 21:47
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-10846: (needs triaging) NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-06-10 Last update: 2026-06-14 19:00
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 1.9.2-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-11 07:00
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for ldns (1.9.0-1 to 1.9.2-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 4 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/l/ldns.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-06-10] Accepted ldns 1.9.2-1 (source) into unstable (Michael Tokarev)
  • [2026-05-30] ldns 1.9.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-29] ldns REMOVED from testing (Debian testing watch)
  • [2026-04-16] Accepted ldns 1.9.0-1 (source) into unstable (Michael Tokarev)
  • [2024-12-31] ldns 1.8.4-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-25] Accepted ldns 1.8.4-2 (source) into unstable (Michael Tokarev)
  • [2024-07-25] ldns 1.8.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-20] Accepted ldns 1.8.4-1 (source) into unstable (Michael Tokarev)
  • [2024-05-04] ldns 1.8.3-2 MIGRATED to testing (Debian testing watch)
  • [2024-05-04] ldns 1.8.3-2 MIGRATED to testing (Debian testing watch)
  • [2024-03-16] Accepted ldns 1.8.3-2 (source) into unstable (Michael Tokarev)
  • [2024-02-29] Accepted ldns 1.8.3-1.1 (source) into unstable (Lukas Märdian)
  • [2024-02-17] Accepted ldns 1.8.3-1.1~exp1 (source) into experimental (Steve Langasek)
  • [2022-09-10] ldns 1.8.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-10] ldns 1.8.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-05] Accepted ldns 1.8.3-1 (source) into unstable (Michael Tokarev)
  • [2022-05-01] ldns 1.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-26] Accepted ldns 1.8.1-1 (source) into unstable (Michael Tokarev)
  • [2022-04-20] ldns 1.7.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-04-13] Accepted ldns 1.7.1-3 (source) into unstable (Daniel Kahn Gillmor) (signed by: dkg@debian.org)
  • [2022-04-09] Accepted ldns 1.7.1-2.1 (source) into unstable (Michael Tokarev)
  • [2022-02-04] Accepted ldns 1.7.0-1+deb9u1 (source amd64) into oldoldstable (Chris Lamb)
  • [2020-07-01] ldns 1.7.1-2 MIGRATED to testing (Debian testing watch)
  • [2020-06-24] Accepted ldns 1.7.1-2 (source) into unstable (Santiago Ruano Rincón)
  • [2020-06-11] Accepted ldns 1.7.1-1 (source amd64) into experimental, experimental (Debian FTP Masters) (signed by: Santiago Ruano Rincón)
  • [2020-03-28] ldns 1.7.0-4.1 MIGRATED to testing (Debian testing watch)
  • [2020-03-20] Accepted ldns 1.7.0-4.1 (source) into unstable (Ivo De Decker)
  • [2019-03-13] ldns 1.7.0-4 MIGRATED to testing (Debian testing watch)
  • [2019-03-10] Accepted ldns 1.7.0-4 (source) into unstable (Ondřej Surý)
  • [2018-10-28] ldns 1.7.0-3.1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 9 11
  • RC: 0
  • I&N: 4 6
  • M&W: 5
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.9.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing