#22308 closed enhancement (fixed)
unbound-1.24.1 (Security fix)
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 11 months ago
| Priority: | normal → elevated |
|---|---|
| Summary: | unbound-1.24.1 → unbound-1.24.1 (Security fix) |
Note:
See TracTickets
for help on using tickets.

Unbound 1.24.1
This security release fixes CVE-2025-11411.
Promiscuous NS RRSets that complement DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone.
The CVE is described here https://nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt
====
The vulnerability is rated at 5.7 Medium,