Home

Software-update: Unbound 1.25.2

Als je een DNS-look-up uitvoert, begint een recursor in eerste instantie met het stellen van de look-upvraag aan een DNS-rootserver. Deze kan dan doorverwijzen naar andere servers, vanaf waar weer doorverwezen kan worden naar andere servers enzovoort, totdat uiteindelijk een server is bereikt die het antwoord weet, of weet dat de look-up niet mogelijk is. Van dit laatste kan sprake zijn als de naam niet bestaat of de servers niet reageren. Het proces van het langslopen van verschillende authoritative servers heet recursie. Unbound is een DNS-recursor met ondersteuning voor moderne standaarden, zoals Query Name Minimisation, Aggressive Use of Dnssec-Validated Cache en authority zones. Versie 1.25.2 is verschenen en hierin zijn de volgende beveiligingsproblemen verholpen:

Bug Fixes
  • Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments.
  • Fix CVE-2026-32665, Remote DNS-over-QUIC denial of service due to quic-size budget bypass.
  • Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP.
  • Fix CVE-2026-41637, Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries.
  • Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time ‘ghost domain’ delegation renewal via glue records.
  • Fix CVE-2026-44621, Libunbound applications configured with ‘unwanted-reply-threshold’ could eventually be abruptly terminated.
  • Fix CVE-2026-44687, Off-by-one error in ‘harden-below-nxdomain’ logic can shadow a stub/forward zone by a legitimate parent’s NXDOMAIN.
  • Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via RRSIG.labels manipulation.
  • Fix CVE-2026-46582, A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path.
  • Fix CVE-2026-50045, ‘max-global-quota’ reset by DNSSEC validation restarts.
  • Fix CVE-2026-50046, Possible heap use-after-free in an error path when a DoT forwarded query is jostled out.
  • Fix CVE-2026-50243, ‘response-ip’/‘rpz’ can rewrite BOGUS answers instead of returning SERVFAIL.
  • Fix CVE-2026-50248, BOGUS configured primary hostname accepted for XFR in auth/rpz zones.
  • Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush.
  • Fix CVE-2026-50252, Possible cache poisoning attack by mapping source port population per thread.
  • Fix CVE-2026-52863, Memory corruption could lead to crash and denial of service.
  • Fix CVE-2026-54478, DNS Cookie bypass when combined with proxy-protocol use.
  • Fix CVE-2026-55708, Privacy/configuration issue when adding local data in views through ‘unbound-control’.
  • Fix CVE-2026-55717, ‘serve-expired-client-timeout’ and ‘response-ip’ CNAME redirect could lead to a crash.
  • Fix CVE-2026-55973, ‘dns-error-reporting: yes’ leads to stack buffer overflow.
  • Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured Unbound.
  • Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2.
  • Fix CVE-2026-56416, Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name.
  • Fix CVE-2026-56444, Degradation of resolution service when ‘discard-timeout’ and ‘serve-expired-client-timeout’ are combined in unusual configuration.
  • Source: Tweakers.net

    Previous

    Next