gpp_maybe
Security update for unbound
SUSE-SLE-Module-Basesystem-15-SP7-2026-3885
This update for unbound fixes the following issues: Update to version 1.25.2. Security issues fixed: - CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875). - CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records (bsc#1271892). - CVE-2026-44621: Libunbound applications configured with `unwanted-reply-threshold` could eventually be abruptly terminated (bsc#1271876). - CVE-2026-44687: Off-by-one error in `harden-below-nxdomain` logic can shadow a stub/forward zone by a legitimate parent's `NXDOMAIN` (bsc#1271893). - CVE-2026-44690: Cross-zone wildcard cache poisoning via `RRSIG.labels` manipulation (bsc#1271877). - CVE-2026-46582: Replay of a wildcard `rrset` as another piece of data triggers poisoning in the server expired reply path (bsc#1271894). - CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882). - CVE-2026-50243: `response-ip`/`rpz` can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880). - CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881). - CVE-2026-50251: Attacker supplied `0.0.0.0`/`::` glue triggers defensive full-cache flush (bsc#1271883). - CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884). - CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with `answer-cookie:yes` is used (bsc#1271895). - CVE-2026-55708: Privacy/configuration issue when adding local data in views through `unbound-control` (bsc#1271896). - CVE-2026-55717: `serve-expired-client-timeout` and `response-ip` CNAME redirect could lead to a crash (bsc#1271886). - CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887). - CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name (bsc#1271889). - CVE-2026-56444: Degradation of resolution service when `discard-timeout` and `serve-expired-client-timeout` are combined in unusual configuration (bsc#1271890). Other updates and bugfixes: - Version 1.25.2: * For a complete list of additional changes see the changelog at https://nlnetlabs.nl/projects/unbound/download/ - Update `unbound.keyring`.
-
Release DateAug 31 2026
-
ReferencesBugzilla: 1271875, 1271876, 1271877, 1271880, 1271881, 1271882, 1271883, 1271884, 1271886, 1271887, 1271889, 1271890, 1271892, 1271893, 1271894, 1271895, 1271896
CVEs: CVE-2026-40622, CVE-2026-40691, CVE-2026-42955, CVE-2026-44621, CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251, CVE-2026-50252, CVE-2026-54478, CVE-2026-55708, CVE-2026-55717, CVE-2026-55990, CVE-2026-56416, CVE-2026-56444 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.7 s390x
-
Packageslibunbound8
Shared library from unboundunbound1.25.2-150600.23.19.1 lock rpm
Validating, recursive, and caching DNS(SEC) resolverunbound-anchor1.25.2-150600.23.19.1 lock src
Unbound Anchor cert management toolsunbound-devel1.25.2-150600.23.19.1 lock rpm
Development files for libunbound1.25.2-150600.23.19.1 lock rpm
Basesystem Module 15.7 aarch64
-
Packageslibunbound8
Shared library from unboundunbound1.25.2-150600.23.19.1 lock rpm
Validating, recursive, and caching DNS(SEC) resolverunbound-anchor1.25.2-150600.23.19.1 lock src
Unbound Anchor cert management toolsunbound-devel1.25.2-150600.23.19.1 lock rpm
Development files for libunbound1.25.2-150600.23.19.1 lock rpm
Basesystem Module 15.7 ppc64le
-
Packageslibunbound8
Shared library from unboundunbound1.25.2-150600.23.19.1 lock rpm
Validating, recursive, and caching DNS(SEC) resolverunbound-anchor1.25.2-150600.23.19.1 lock src
Unbound Anchor cert management toolsunbound-devel1.25.2-150600.23.19.1 lock rpm
Development files for libunbound1.25.2-150600.23.19.1 lock rpm
Basesystem Module 15.7 x86_64
-
Packageslibunbound8
Shared library from unboundunbound1.25.2-150600.23.19.1 lock rpm
Validating, recursive, and caching DNS(SEC) resolverunbound-anchor1.25.2-150600.23.19.1 lock src
Unbound Anchor cert management toolsunbound-devel1.25.2-150600.23.19.1 lock rpm
Development files for libunbound1.25.2-150600.23.19.1 lock rpm