{"id":"SUSE-SU-2026:23215-1","summary":"Security update for unbound","details":"This update for unbound fixes the following issues:\n\nUpdate to version 1.25.2.\n\nSecurity issues fixed:\n\n- CVE-2026-14586: DoS via assertion in `libngtcp2` for DNS-over-QUIC environments with high concurrency (bsc#1271879).\n- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass (bsc#1271873).\n- CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875).\n- CVE-2026-41637: Degradation of resolution service due to improperly accounted client-terminated DNS-over-QUIC queries\n  (bsc#1271891).\n- CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records\n  (bsc#1271892).\n- CVE-2026-44621: Libunbound applications configured with `unwanted-reply-threshold` could eventually be abruptly\n  terminated (bsc#1271876).\n- CVE-2026-44687: Off-by-one error in `harden-below-nxdomain` logic can shadow a stub/forward zone by a legitimate\n  parent's `NXDOMAIN` (bsc#1271893).\n- CVE-2026-44690: Cross-zone wildcard cache poisoning via `RRSIG.labels` manipulation (bsc#1271877).\n- CVE-2026-46582: Replay of a wildcard `rrset` as another piece of data triggers poisoning in the server expired reply\n  path (bsc#1271894).\n- CVE-2026-50045: `max-global-quota` bypass via single client queries for a deeply nested name under a DNSSEC-signed\n  parent (bsc#1271878).\n- CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882).\n- CVE-2026-50243: `response-ip`/`rpz` can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).\n- CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881).\n- CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers defensive full-cache flush (bsc#1271883).\n- CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884).\n- CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with `answer-cookie:yes` is used (bsc#1271895).\n- CVE-2026-55708: Privacy/configuration issue when adding local data in views through `unbound-control` (bsc#1271896).\n- CVE-2026-55717: `serve-expired-client-timeout` and `response-ip` CNAME redirect could lead to a crash (bsc#1271886).\n- CVE-2026-55973: DoS due to stack overflow triggered crash when `dns-error-reporting: yes` is set (bsc#1271874).\n- CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887).\n- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control reacheable assertion failure in `libngtcp2` (bsc#1271888).\n- CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name\n  (bsc#1271889).\n- CVE-2026-56444: Degradation of resolution service when `discard-timeout` and `serve-expired-client-timeout` are\n  combined in unusual configuration (bsc#1271890).\n\nOther updates and bugfixes:\n\n- Version 1.25.2:\n  + Features:\n    * TTL behavior changes: cached records reaching TTL 0 are expired;\n      TTL 0 upstream answers are no longer cached by cachedb;\n      serve-expired-reply-ttl is now capped by the original TTL value;\n      TTL decoding updated to adhere to RFC 8767 section 4\n    * Add new statistics: num.queries.replyaddr_limit and\n      requestlist.current.replies\n    * Add 'log-thread-id' configuration option to log the system-wide\n      Linux thread ID for easier debugging\n    * Add ECC-GOST12 support per RFC 9558 (available as\n      contrib/gost12.patch)\n    * Allow synthesized DNAME TTL=0 to be served from cache within a\n      1-second grace period, reducing recursion for TTL=0 DNAMEs\n      (RFC 2308)\n    * Fix DoT/DoH/DoQ to reload certificates on config reload without\n      requiring a full restart; fast_reload now supports changes to\n      tls-service-key, tls-service-pem and tls-cert-bundle\n    * Allow ip@port notation in control-interface configuration\n    * Add iter-scrub-rrsig option (default: 8) to limit the number of\n      RRSIGs processed by the scrubber\n    * Add 'tls-protocols' configuration option to select which TLS\n      protocol versions are used; TLSv1.2 is re-enabled by default\n    * Add pthread_setname_np support for named threads\n  + Bug Fixes:\n    * Fix handle leak in pythonmod on pythonmod_init\n    * Fix crash when mesh_detect_cycle_found() is called with no mesh\n      state\n    * Fix modstack_call_init to use the original string when it has\n      changed\n    * Fix fr_atomic_copy_cfg\n    * Fix auth-zone empty label for $ORIGIN when downloading via HTTP\n    * Fix respip and dns64 to be usable simultaneously; RPZ now works\n      with DNS64\n    * Fix HTTPS and QUIC not being enabled when port is listed in\n      interface-automatic-ports\n    * Allow wait-limit-cookie: 0 to disable cookie-validated wait limits\n    * Fix FIPS mode in OpenSSL causing unit test failure\n    * Fix discard-timeout to only drop UDP, not stream connections\n    * Reply with SERVFAIL when the wait-limit is exceeded\n    * Add extended DNS error code for invalid query type\n    * Replace deprecated SWIG $function with $action\n    * Log a warning for possible circular dependency when using hostnames\n      in stub/forward zones\n    * Fix infra cache for NAT64 by moving NAT64 synthesis to the\n      delegation point when adding target addresses\n    * Fix discard-timeout packet accounting in the mesh area\n    * Update IANA portlist\n    * Copy DNSTAP configuration from daemon to workers after fast_reload\n    * Fix HTTP/2 stream mesh state removal and drop handling for\n      postpone_drop and send failures\n    * Log THROWAWAY and (DNSSEC) LAME responses with clearer\n      categorization in log output\n    * Fix EDE removal logic consistency between encoding errors and\n      encoding replies\n    * Fix EDNS subnet scope-zero queries not being stored when\n      forward-no-cache or stub-no-cache is set\n    * Do not initialize quic_table unless QUIC is enabled\n    * Fix fast_reload to copy iter_scrub_ns, iter_scrub_cname and\n      max_global_quota options\n    * Fix allow-notify entries with hostnames to be copied after\n      IPv4/IPv6 lookup; fix skipping hostname lookups when only URLs\n      are configured\n    * Fix NAT64 inconsistency with do-not-query-address during retries\n    * Fix cachedb aggressive negative responses not setting the RA flag\n    * Fix root key priming failure after loading RPZ zones containing\n      ZONEMD RRtype\n    * Fix local-zone always_refuse to also block DS queries\n    * Fix cache lookup/store in external cachedb when forwarder/stub\n      uses the no-cache option\n    * Fix cachedb returning expired bogus data as non-bogus\n    * Fix validator unchecked state handling with validation recursion\n      and EDNS subnet\n    * Fix DNAME lookup flag and assertion in expired calculation debug\n      routine\n    * Fix DNS rebinding bypass via SVCB/HTTPS records; private-address\n      now also elides SVCB and HTTPS records matching the filter\n    * Warn for unused 'nodefault' local-zone configuration in\n      unbound-checkconf\n    * Fix lock/unlock for view in memory error handling\n    * Apply cache TTL policy to DNAME and synthesized CNAME on the\n      wire path\n    * Fix detection of HTTP listening port in fast_reload\n    * Fix ignoring out-of-zone DNAME records for CNAME synthesis\n    * Fix invalid HTTP content length/chunk size checks and RR rdata\n      field length validation in zone transfer, preventing heap\n      buffer-overflow read errors\n    * Fix defense in depth for service callback with empty packet\n    * Fix shared memory statistics with threads\n    * Fix EDNS client subnet to not store SERVFAIL in the global cache\n      after a failed lookup; stores a short-lived failure entry in the\n      subnet cache instead\n    * Fix memory corruption related core dumps when alloc_reg_obtain\n      encounters an empty list\n    * Fix RFC 7766 compliance when client sends EOF over TCP\n    * Fix DoH session cleanup when the same query appears on multiple\n      streams\n    * Fix TLS context setup for tls-service-pem\n    * Fix TTL comparisons in rdata_copy for 32-bit signed/unsigned values\n    * Fix memory leak in subnet SERVFAIL store\n    * Fix for the Jiggle Attack: server now answers errors for error\n      cases and no longer reflects parts of the incoming query\n    * Fix EDNS extended RCODE reflection: server no longer echoes\n      extended RCODE values after CHAOS class queries\n    * Fix iterator RCODE handling of YXDOMAIN: only accept YXDOMAIN\n      answers that contain a DNAME record\n    * Fix missing bounds check when decompressing dnames for downloaded\n      authority zones, preventing malformed content from truncated AXFR\n      packets\n    * Fix upstream TLS connections being reused for different names at\n      the same IP address\n    * Fix to disallow signatures with revoked DNSKEYs\n    * Fix DNAME with unsigned CNAME to check for the correct match,\n      preventing certain zone configurations from granting secure status\n      to unchecked CNAMEs\n    * Fix wildcard CNAME handling in the chain of trust\n    * Fix buffer overrun in doq_repinfo_retrieve_localaddr()\n  + Packaging changes:\n    * Update keyring to new NLnet Labs release signing key\n","modified":"2026-08-27T18:23:26.893663445Z","published":"2026-08-10T15:26:22Z","related":["CVE-2026-14586","CVE-2026-32665","CVE-2026-40622","CVE-2026-40691","CVE-2026-41637","CVE-2026-42955","CVE-2026-44621","CVE-2026-44687","CVE-2026-44690","CVE-2026-46582","CVE-2026-50045","CVE-2026-50046","CVE-2026-50243","CVE-2026-50248","CVE-2026-50251","CVE-2026-50252","CVE-2026-54478","CVE-2026-55708","CVE-2026-55717","CVE-2026-55973","CVE-2026-55990","CVE-2026-55991","CVE-2026-56416","CVE-2026-56444"],"upstream":["CVE-2026-14586","CVE-2026-32665","CVE-2026-40622","CVE-2026-40691","CVE-2026-41637","CVE-2026-42955","CVE-2026-44621","CVE-2026-44687","CVE-2026-44690","CVE-2026-46582","CVE-2026-50045","CVE-2026-50046","CVE-2026-50243","CVE-2026-50248","CVE-2026-50251","CVE-2026-50252","CVE-2026-54478","CVE-2026-55708","CVE-2026-55717","CVE-2026-55973","CVE-2026-55990","CVE-2026-55991","CVE-2026-56416","CVE-2026-56444"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623215-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271874"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271875"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271876"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271877"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271879"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271883"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271884"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271887"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271889"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271890"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271891"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271892"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271894"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50248"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56444"}],"affected":[{"package":{"name":"unbound","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"unbound-devel":"1.25.2-160000.1.1","libunbound8":"1.25.2-160000.1.1","python3-unbound":"1.25.2-160000.1.1","unbound":"1.25.2-160000.1.1","unbound-anchor":"1.25.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23215-1.json"}},{"package":{"name":"unbound","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"python3-unbound":"1.25.2-160000.1.1","unbound":"1.25.2-160000.1.1","unbound-anchor":"1.25.2-160000.1.1","unbound-devel":"1.25.2-160000.1.1","libunbound8":"1.25.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23215-1.json"}}],"schema_version":"1.9.0"}