{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0451",
  "published": "2026-09-25T05:02:40Z",
  "modified": "2026-09-25T03:55:44Z",
  "summary": "Updated unbound packages fixes security vulnerabilities",
  "details": "Heap buffer overflow and possible Remote Code Execution when digesting\nDNSKEY\nPossible heap buffer overflow during DNSSEC canonicalization\nCNAME synthesis could lead to heap corruption\nPossible ZONEMD verification bypass window\nUse-after-free in DoQ stream output buffer on reset re-transmission\nPossible degradation of service from continuous queries on the same\nTCP/DoT connection\nUse-after-free in DoH stream cleanup code path\nRetrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks\non DNSSEC\n'serve-expired' can bypass Unbound 'wait-limit'\nRemote DNS-over-QUIC denial of service due to 'quic-size' budget bypass\nPacket of death for DNSCrypt over TCP\nCross-zone wildcard cache poisoning via RRSIG.labels manipulation\n'dns-error-reporting: yes' leads to stack buffer overflow\nAssertion in libngtcp2 when under pressure in high concurrency\nDNS-over-QUIC environments\nLibunbound applications configured with 'unwanted-reply-threshold' could\neventually be abruptly terminated\n'max-global-quota' reset by DNSSEC validation restarts\nPossible heap use-after-free in an error path when a DoT forwarded query\nis jostled out\n'response-ip'/'rpz' can rewrite BOGUS answers instead of returning\nSERVFAIL\nBOGUS configured primary hostname accepted for XFR in auth/rpz zones\nDate:\nAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache\nflush\nPossible cache poisoning attack by mapping source port population per\nthread\nMemory corruption could lead to crash and denial of service\n'serve-expired-client-timeout' and 'response-ip' CNAME redirect could\nlead to a crash\nPacket of death for a DNSCrypt misconfigured Unbound\nRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2\nPossible heap buffer overflow when validator canonicalizes RDATA that\ncontains domain name\nDegradation of resolution service when 'discard-timeout' and\n'serve-expired-client-timeout' are combined in unusual configuration\nDegradation of resolution service from improperly accounted\nclient-terminated DNS-over-QUIC queries\nExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records\ndisallowing a one-time 'ghost domain' delegation renewal via glue\nrecords\nOff-by-one error in 'harden-below-nxdomain' logic can shadow a\nstub/forward zone by a legitimate parent's NXDOMAIN\nA wildcard replay, as another piece of data, triggers poisoning in the\nserve expired reply path\nDNS Cookie bypass when combined with proxy-protocol use\nPrivacy/configuration issue when adding local data in views through\n'unbound-control'\nPossible arbitrary code execution during DNSSEC validation\nHeap overflow with multiple NSID, COOKIE, PADDING EDNS options\nCrash during DNSSEC validation of malicious content\nDate:\nPacket of death with DNSCrypt\nAnother \"ghost domain names\" attack variant\nLong list of incoming EDNS options degrades performance\nJostle logic bypass degrades resolution performance\nDegradation of service with unbounded NSEC3 hash calculations\nPossible cache poisoning via promiscuous records for the authority\nsection\nUnbounded name compression in certain cases causes degradation of\nservice\nUse after free and crash under special conditions in RPZ code\nPossible domain hijacking via promiscuous records in the authority\nsection\nCache poisoning via the ECS-enabled Rebirthday Attack\nUnbounded name compression could lead to Denial of Service\nUnbound vulnerable to the \"DNSBomb\" pulsing DoS amplification attack\nDenial of service when trimming EDE text on positive replies\nDNSSEC verification complexity can be exploited to exhaust CPU resources\nand stall DNS resolvers\nNSEC3 closest encloser proof can exhaust CPU\nNon-Responsive Delegation Attack\nNovel \"ghost domain names\" attack by updating almost expired delegation\ninformation\nNovel \"ghost domain names\" attack by introducing subdomain delegations\nLocal symlink attack\nVulnerability in Domain Parse\nNXNSAttack\nVulnerability in IPSEC module\nVulnerability in parsing NOTIFY queries\nVulnerability in the processing of wildcard synthesized NSEC records\nNo limit to delegation chaining\nGhost domain names attack\nIncorrect proof processing for NSEC3-signed zone\nProcessing of duplicate CNAME records in a signed zone\nEmpty error packet handling assertion failure\n",
  "upstream": [
    "CVE-2026-14586",
    "CVE-2026-32665",
    "CVE-2026-40622",
    "CVE-2026-40691",
    "CVE-2026-41637",
    "CVE-2026-42955",
    "CVE-2026-44621",
    "CVE-2026-44687",
    "CVE-2026-44690",
    "CVE-2026-46582",
    "CVE-2026-50045",
    "CVE-2026-50046",
    "CVE-2026-50243",
    "CVE-2026-50248",
    "CVE-2026-50251",
    "CVE-2026-50252",
    "CVE-2026-52863",
    "CVE-2026-54478",
    "CVE-2026-55708",
    "CVE-2026-55717",
    "CVE-2026-55973",
    "CVE-2026-55990",
    "CVE-2026-55991",
    "CVE-2026-56416",
    "CVE-2026-56444",
    "CVE-2026-77860",
    "CVE-2026-77955",
    "CVE-2026-78227",
    "CVE-2026-80225",
    "CVE-2026-81634",
    "CVE-2026-81642",
    "CVE-2026-82717",
    "CVE-2026-82720",
    "CVE-2026-85501"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0451.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36346"
    },
    {
      "type": "ADVISORY",
      "url": "https://nlnetlabs.nl/projects/unbound/security-advisories/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "unbound",
        "purl": "pkg:rpm/mageia/unbound?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.26.1-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "unbound",
        "purl": "pkg:rpm/mageia/unbound?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.26.1-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
