rpm package
opensuse/unbound&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/unbound&distro=openSUSE%20Tumbleweed
Vulnerabilities (61)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-85501 | Med | 5.3 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including | |
| CVE-2026-82720 | Med | 5.9 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH | |
| CVE-2026-82717 | Cri | 9.8 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream respon | |
| CVE-2026-81642 | Cri | 9.8 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the dig | |
| CVE-2026-81634 | Hig | 7.5 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor | |
| CVE-2026-80225 | Med | 5.3 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT conne | |
| CVE-2026-78227 | Med | 6.5 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into | |
| CVE-2026-77955 | Med | 4.4 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the Z | |
| CVE-2026-77860 | Low | 3.7 | < 1.26.1-1.1 | 1.26.1-1.1 | Sep 16, 2026 | In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A ma | |
| CVE-2026-56444 | Med | 5.9 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged clien | |
| CVE-2026-56416 | Med | 4.8 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to | |
| CVE-2026-55991 | Med | 5.9 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is cau | |
| CVE-2026-55990 | Med | 5.9 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's | |
| CVE-2026-55973 | Hig | 7.5 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed | |
| CVE-2026-55717 | Med | 5.9 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain c | |
| CVE-2026-55708 | Low | 3.1 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creati | |
| CVE-2026-54478 | Low | 3.7 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obt | |
| CVE-2026-52863 | Med | 5.9 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is u | |
| CVE-2026-50252 | Cri | 9.3 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secr | |
| CVE-2026-50251 | Med | 5.3 | < 1.25.2-1.1 | 1.25.2-1.1 | Jul 22, 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingl |
- affected < 1.26.1-1.1fixed 1.26.1-1.1
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including
- affected < 1.26.1-1.1fixed 1.26.1-1.1
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream respon
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the dig
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT conne
- affected < 1.26.1-1.1fixed 1.26.1-1.1
NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the Z
- affected < 1.26.1-1.1fixed 1.26.1-1.1
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A ma
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged clien
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is cau
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain c
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creati
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obt
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is u
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secr
- affected < 1.25.2-1.1fixed 1.25.2-1.1
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingl
Page 1 of 4