Re: [BLFS Trac] #23229: unbound-1.25.1 (sysv only) (was: unbound-1.25.0 (sysv only))
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23229: unbound-1.25.1 (sysv only)
-------------------------+-----------------------------
Reporter: Bruce Dubbs | Owner: Randy McMurchy
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-----------------------------
Changes (by Douglas R. Reno):
* priority: normal => high
* summary: unbound-1.25.0 (sysv only) => unbound-1.25.1 (sysv only)
Comment:
Now 1.25.1, with a swath of security vulnerability fixes. One of them is
rated as Critical due to remote code execution when simply validating
DNSSEC responses.
{{{
CVE-2026-33278 - severity: CRITICAL
Possible remote code execution during DNSSEC validation
CVE-2026-42944 - severity: HIGH
Heap overflow and crash with multiple nsid, cookie, padding EDNS options
CVE-2026-42959 - severity: HIGH
Crash during DNSSEC validation of malicious content
CVE-2026-32792 - severity: MEDIUM
Packet of death with DNSCrypt (feasibility very low)
CVE-2026-40622 - severity: MEDIUM
"Ghost domain name" variant
CVE-2026-41292 - severity: MEDIUM
Parsing a long list of incoming EDNS options degrades performance
CVE-2026-42534 - severity: MEDIUM
Jostle logic bypass degrades resolution performance
CVE-2026-42923 - severity: MEDIUM
Degradation of service with unbounded NSEC3 hash calculations
CVE-2026-42960 - severity: MEDIUM
Possible cache poisoning attack while following delegation
CVE-2026-44390 - severity: MEDIUM
Unbounded name compression in certain cases causes degradation of service
CVE-2026-44608 - severity: MEDIUM
Use after free and crash in RPZ code (special requirements apply)
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23229#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page