[Git][security-tracker-team/security-tracker][master] Document incomplete fix for CVE-2025-11411/unbound

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Nov 26 16:52:24 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a9663e9 by Salvatore Bonaccorso at 2025-11-26T17:37:12+01:00
Document incomplete fix for CVE-2025-11411/unbound

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10205,6 +10205,10 @@ CVE-2025-11411 (NLnet Labs Unbound up to and including version 1.24.0 is vulnera
 	- unbound 1.24.1-1
 	NOTE: https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt
 	NOTE: Fixed by: https://github.com/NLnetLabs/unbound/commit/a33f0638e1dacf2633cf2292078a674576bca852 (release-1.24.1)
+	NOTE: The original fix for CVE-2025-11411 was incomplete and required a followup
+	NOTE: (cf. https://bugs.debian.org/1121446) to include YXDOMAIN and non-referral
+	NOTE: nodata answers in the mitigation as well:
+	NOTE: Followup: https://github.com/NLnetLabs/unbound/commit/f6269baa605d31859f28770e01a24e3677e5f82c (release-1.24.2)
 CVE-2025-11086 (The Academy LMS \u2013 WordPress LMS Plugin for Complete eLearning Sol ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-10138 (The This-or-That plugin for WordPress is vulnerable to Stored Cross-Si ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a9663e9173d79bf46e9e13f9e717245742cbc3e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a9663e9173d79bf46e9e13f9e717245742cbc3e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251126/9aac62fb/attachment.htm>


More information about the debian-security-tracker-commits mailing list