Advisories ยป MGASA-2026-0451

Updated unbound packages fixes security vulnerabilities

Publication date: 25 Sep 2026
Modification date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14586 , CVE-2026-32665 , CVE-2026-40622 , CVE-2026-40691 , CVE-2026-41637 , CVE-2026-42955 , CVE-2026-44621 , CVE-2026-44687 , CVE-2026-44690 , CVE-2026-46582 , CVE-2026-50045 , CVE-2026-50046 , CVE-2026-50243 , CVE-2026-50248 , CVE-2026-50251 , CVE-2026-50252 , CVE-2026-52863 , CVE-2026-54478 , CVE-2026-55708 , CVE-2026-55717 , CVE-2026-55973 , CVE-2026-55990 , CVE-2026-55991 , CVE-2026-56416 , CVE-2026-56444 , CVE-2026-77860 , CVE-2026-77955 , CVE-2026-78227 , CVE-2026-80225 , CVE-2026-81634 , CVE-2026-81642 , CVE-2026-82717 , CVE-2026-82720 , CVE-2026-85501

Description

Heap buffer overflow and possible Remote Code Execution when digesting
DNSKEY
Possible heap buffer overflow during DNSSEC canonicalization
CNAME synthesis could lead to heap corruption
Possible ZONEMD verification bypass window
Use-after-free in DoQ stream output buffer on reset re-transmission
Possible degradation of service from continuous queries on the same
TCP/DoT connection
Use-after-free in DoH stream cleanup code path
Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks
on DNSSEC
'serve-expired' can bypass Unbound 'wait-limit'
Remote DNS-over-QUIC denial of service due to 'quic-size' budget bypass
Packet of death for DNSCrypt over TCP
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
'dns-error-reporting: yes' leads to stack buffer overflow
Assertion in libngtcp2 when under pressure in high concurrency
DNS-over-QUIC environments
Libunbound applications configured with 'unwanted-reply-threshold' could
eventually be abruptly terminated
'max-global-quota' reset by DNSSEC validation restarts
Possible heap use-after-free in an error path when a DoT forwarded query
is jostled out
'response-ip'/'rpz' can rewrite BOGUS answers instead of returning
SERVFAIL
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Date:
Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache
flush
Possible cache poisoning attack by mapping source port population per
thread
Memory corruption could lead to crash and denial of service
'serve-expired-client-timeout' and 'response-ip' CNAME redirect could
lead to a crash
Packet of death for a DNSCrypt misconfigured Unbound
Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Possible heap buffer overflow when validator canonicalizes RDATA that
contains domain name
Degradation of resolution service when 'discard-timeout' and
'serve-expired-client-timeout' are combined in unusual configuration
Degradation of resolution service from improperly accounted
client-terminated DNS-over-QUIC queries
Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records
disallowing a one-time 'ghost domain' delegation renewal via glue
records
Off-by-one error in 'harden-below-nxdomain' logic can shadow a
stub/forward zone by a legitimate parent's NXDOMAIN
A wildcard replay, as another piece of data, triggers poisoning in the
serve expired reply path
DNS Cookie bypass when combined with proxy-protocol use
Privacy/configuration issue when adding local data in views through
'unbound-control'
Possible arbitrary code execution during DNSSEC validation
Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
Crash during DNSSEC validation of malicious content
Date:
Packet of death with DNSCrypt
Another "ghost domain names" attack variant
Long list of incoming EDNS options degrades performance
Jostle logic bypass degrades resolution performance
Degradation of service with unbounded NSEC3 hash calculations
Possible cache poisoning via promiscuous records for the authority
section
Unbounded name compression in certain cases causes degradation of
service
Use after free and crash under special conditions in RPZ code
Possible domain hijacking via promiscuous records in the authority
section
Cache poisoning via the ECS-enabled Rebirthday Attack
Unbounded name compression could lead to Denial of Service
Unbound vulnerable to the "DNSBomb" pulsing DoS amplification attack
Denial of service when trimming EDE text on positive replies
DNSSEC verification complexity can be exploited to exhaust CPU resources
and stall DNS resolvers
NSEC3 closest encloser proof can exhaust CPU
Non-Responsive Delegation Attack
Novel "ghost domain names" attack by updating almost expired delegation
information
Novel "ghost domain names" attack by introducing subdomain delegations
Local symlink attack
Vulnerability in Domain Parse
NXNSAttack
Vulnerability in IPSEC module
Vulnerability in parsing NOTIFY queries
Vulnerability in the processing of wildcard synthesized NSEC records
No limit to delegation chaining
Ghost domain names attack
Incorrect proof processing for NSEC3-signed zone
Processing of duplicate CNAME records in a signed zone
Empty error packet handling assertion failure
                

References

SRPMS

10/core

9/core