Opened 5 months ago

Closed 3 months ago

#23229 closed enhancement (fixed)

unbound-1.25.1 (sysv only)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (7)

comment:1 by Bruce Dubbs, 5 months ago

Owner: changed from blfs-book to Randy McMurchy

comment:2 by Bruce Dubbs, 5 months ago

Summary: unbound-1.25.0 → unbound-1.25.0 (sysv only)

comment:3 by Douglas R. Reno, 5 months ago

Priority: normal → high
Summary: unbound-1.25.0 (sysv only) → unbound-1.25.1 (sysv only)

Now 1.25.1, with a swath of security vulnerability fixes. One of them is rated as Critical due to remote code execution when simply validating DNSSEC responses.

CVE-2026-33278 - severity: CRITICAL
Possible remote code execution during DNSSEC validation

CVE-2026-42944 - severity: HIGH
Heap overflow and crash with multiple nsid, cookie, padding EDNS options

CVE-2026-42959 - severity: HIGH
Crash during DNSSEC validation of malicious content

CVE-2026-32792 - severity: MEDIUM
Packet of death with DNSCrypt (feasibility very low)

CVE-2026-40622 - severity: MEDIUM
"Ghost domain name" variant

CVE-2026-41292 - severity: MEDIUM
Parsing a long list of incoming EDNS options degrades performance

CVE-2026-42534 - severity: MEDIUM
Jostle logic bypass degrades resolution performance

CVE-2026-42923 - severity: MEDIUM
Degradation of service with unbounded NSEC3 hash calculations

CVE-2026-42960 - severity: MEDIUM
Possible cache poisoning attack while following delegation

CVE-2026-44390 - severity: MEDIUM
Unbounded name compression in certain cases causes degradation of service

CVE-2026-44608 - severity: MEDIUM
Use after free and crash in RPZ code (special requirements apply)

comment:4 by zeckma, 5 months ago

Owner: changed from Randy McMurchy to zeckma
Status: new → assigned

comment:5 by zeckma, 5 months ago

Taking this ticket since we haven't heard from Randy and I have a system capable of testing Unbound properly.

comment:6 by zeckma, 5 months ago

Owner: changed from zeckma to SecurityAdvisory
Status: assigned → new

Fixed at d7ab8e88000c79fc8779381e4ffbef230f17a191. Leaving open for SA.

comment:7 by Douglas R. Reno, 3 months ago

Resolution: → fixed
Status: new → closed

SA-12.4-113 issued

Note that this is a 12.4 specific advisory as 13.0 does not carry unbound (since 13.0 was systemd only)

Note: See TracTickets for help on using tickets.