{"id":"SUSE-SU-2026:23360-1","summary":"Security update for unbound","details":"This update for unbound fixes the following issues:\n\nUpdate to version 1.25.2.\n\nSecurity issues fixed:\n\n- CVE-2026-14586: DoS via assertion in `libngtcp2` for DNS-over-QUIC environments with high concurrency (bsc#1271879).\n- CVE-2026-32665: Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass (bsc#1271873).\n- CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875).\n- CVE-2026-41637: Degradation of resolution service due to improperly accounted client-terminated DNS-over-QUIC queries\n  (bsc#1271891).\n- CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records\n  (bsc#1271892).\n- CVE-2026-44621: Libunbound applications configured with `unwanted-reply-threshold` could eventually be abruptly\n  terminated (bsc#1271876).\n- CVE-2026-44687: Off-by-one error in `harden-below-nxdomain` logic can shadow a stub/forward zone by a legitimate\n  parent's `NXDOMAIN` (bsc#1271893).\n- CVE-2026-44690: Cross-zone wildcard cache poisoning via `RRSIG.labels` manipulation (bsc#1271877).\n- CVE-2026-46582: Replay of a wildcard `rrset` as another piece of data triggers poisoning in the server expired reply\n  path (bsc#1271894).\n- CVE-2026-50045: `max-global-quota` bypass via single client queries for a deeply nested name under a DNSSEC-signed\n  parent (bsc#1271878).\n- CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882).\n- CVE-2026-50243: `response-ip`/`rpz` can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).\n- CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881).\n- CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers defensive full-cache flush (bsc#1271883).\n- CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884).\n- CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with `answer-cookie:yes` is used (bsc#1271895).\n- CVE-2026-55708: Privacy/configuration issue when adding local data in views through `unbound-control` (bsc#1271896).\n- CVE-2026-55717: `serve-expired-client-timeout` and `response-ip` CNAME redirect could lead to a crash (bsc#1271886).\n- CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887).\n- CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control reacheable assertion failure in `libngtcp2` (bsc#1271888).\n- CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name\n  (bsc#1271889).\n- CVE-2026-56444: Degradation of resolution service when `discard-timeout` and `serve-expired-client-timeout` are\n  combined in unusual configuration (bsc#1271890).\n\nOther updates and bugfixes:\n\n- Version 1.25.2:\n  * For a complete list of additional changes see the changelog at https://nlnetlabs.nl/projects/unbound/download/.\n- Update `unbound.keyring`.\n","modified":"2026-09-10T18:23:37.565671513Z","published":"2026-08-26T14:27:41Z","related":["CVE-2026-14586","CVE-2026-32665","CVE-2026-40622","CVE-2026-40691","CVE-2026-41637","CVE-2026-42955","CVE-2026-44621","CVE-2026-44687","CVE-2026-44690","CVE-2026-46582","CVE-2026-50045","CVE-2026-50046","CVE-2026-50243","CVE-2026-50248","CVE-2026-50251","CVE-2026-50252","CVE-2026-54478","CVE-2026-55708","CVE-2026-55717","CVE-2026-55990","CVE-2026-55991","CVE-2026-56416","CVE-2026-56444"],"upstream":["CVE-2026-14586","CVE-2026-32665","CVE-2026-40622","CVE-2026-40691","CVE-2026-41637","CVE-2026-42955","CVE-2026-44621","CVE-2026-44687","CVE-2026-44690","CVE-2026-46582","CVE-2026-50045","CVE-2026-50046","CVE-2026-50243","CVE-2026-50248","CVE-2026-50251","CVE-2026-50252","CVE-2026-54478","CVE-2026-55708","CVE-2026-55717","CVE-2026-55990","CVE-2026-55991","CVE-2026-56416","CVE-2026-56444"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623360-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271875"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271876"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271877"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271879"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271883"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271884"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271887"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271889"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271890"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271891"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271892"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271894"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50248"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56444"}],"affected":[{"package":{"name":"unbound","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-1.1"}]}],"ecosystem_specific":{"binaries":[{"libunbound8":"1.25.2-1.1","unbound-anchor":"1.25.2-1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23360-1.json"}}],"schema_version":"1.9.0"}