[Git][security-tracker-team/security-tracker][master] Track fixes for unbound via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 22 20:57:35 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f2419b21 by Salvatore Bonaccorso at 2026-07-22T21:57:17+02:00
Track fixes for unbound via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -180,76 +180,76 @@ CVE-2026-64600 [xfs: resample the data fork mapping after cycling ILOCK]
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/14
 	NOTE: https://git.kernel.org/linus/2f4acd0fcd862e22eab45690ec2c08c80b6ef2e7 (7.2-rc4)
 CVE-2026-32665 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstre ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-40691 (In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is  ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-44690 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient v ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-55973 (In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-err ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-14586 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-Q ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-44621 (With NLnet Labs Unbound up to and including version 1.25.1, applicatio ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50045 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single clie ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50046 (In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS serve ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50243 (In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound i ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50248 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/r ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50251 (In NLnet Labs Unbound up to and including version 1.25.1, when 'unwant ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-50252 (In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source po ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-52863 (In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that ma ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-55717 (In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-e ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-55990 (In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnsc ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-55991 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unau ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-56416 (In NLnet Labs Unbound up to and including version 1.25.1, when the val ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-56444 (In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound  ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-41637 (In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client termin ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-42955 (In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vul ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-44687 (In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forwa ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-46582 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a  ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-54478 (In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound  ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-55708 (In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_loca ...)
-	- unbound <unfixed>
+	- unbound 1.25.2-1
 	NOTE: https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430
 CVE-2026-10723 (BIND may accept incorrect child-zone NSEC3 records as valid, which cou ...)
 	- bind9 <unfixed>
@@ -49807,6 +49807,7 @@ CVE-2026-40622 (NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has
 	- unbound 1.25.1-1 (bug #1137187)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/05/20/5
 	NOTE: https://nlnetlabs.nl/downloads/unbound/CVE-2026-40622.txt
+	NOTE: Followup fix in 1.25.2 to also clamp the TTL of A/AAAA records
 CVE-2026-32792 (NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a deni ...)
 	{DSA-6304-1}
 	- unbound 1.25.1-1 (bug #1137187; unimportant)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2419b2114e7a5ca552d6181ee9038afe833bfcf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f2419b2114e7a5ca552d6181ee9038afe833bfcf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/56266642/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list