- The code repository continues with 1.26.2 under development,

that includes the changes from before the 1.26.1 commits.
This commit is contained in:
W.C.A. Wijngaards
2026-09-16 10:34:06 +02:00
parent a6586ced92
commit b45c8b4b53
3 changed files with 51 additions and 14 deletions
Vendored
+13 -12
View File
@@ -1,6 +1,6 @@
#! /bin/sh
# Guess values for system-dependent variables and create Makefiles.
# Generated by GNU Autoconf 2.71 for unbound 1.26.1.
# Generated by GNU Autoconf 2.71 for unbound 1.26.2.
#
# Report bugs to <unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues>.
#
@@ -622,8 +622,8 @@ MAKEFLAGS=
# Identity of this package.
PACKAGE_NAME='unbound'
PACKAGE_TARNAME='unbound'
PACKAGE_VERSION='1.26.1'
PACKAGE_STRING='unbound 1.26.1'
PACKAGE_VERSION='1.26.2'
PACKAGE_STRING='unbound 1.26.2'
PACKAGE_BUGREPORT='unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues'
PACKAGE_URL=''
@@ -1513,7 +1513,7 @@ if test "$ac_init_help" = "long"; then
# Omit some internal or obsolete options to make the list less imposing.
# This message is too long to be a string in the A/UX 3.1 sh.
cat <<_ACEOF
\`configure' configures unbound 1.26.1 to adapt to many kinds of systems.
\`configure' configures unbound 1.26.2 to adapt to many kinds of systems.
Usage: $0 [OPTION]... [VAR=VALUE]...
@@ -1579,7 +1579,7 @@ fi
if test -n "$ac_init_help"; then
case $ac_init_help in
short | recursive ) echo "Configuration of unbound 1.26.1:";;
short | recursive ) echo "Configuration of unbound 1.26.2:";;
esac
cat <<\_ACEOF
@@ -1832,7 +1832,7 @@ fi
test -n "$ac_init_help" && exit $ac_status
if $ac_init_version; then
cat <<\_ACEOF
unbound configure 1.26.1
unbound configure 1.26.2
generated by GNU Autoconf 2.71
Copyright (C) 2021 Free Software Foundation, Inc.
@@ -2489,7 +2489,7 @@ cat >config.log <<_ACEOF
This file contains any messages produced by compilers while
running configure, to aid debugging if configure makes a mistake.
It was created by unbound $as_me 1.26.1, which was
It was created by unbound $as_me 1.26.2, which was
generated by GNU Autoconf 2.71. Invocation command line was
$ $0$ac_configure_args_raw
@@ -3253,11 +3253,11 @@ UNBOUND_VERSION_MAJOR=1
UNBOUND_VERSION_MINOR=26
UNBOUND_VERSION_MICRO=1
UNBOUND_VERSION_MICRO=2
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=40
LIBUNBOUND_REVISION=41
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -3365,6 +3365,7 @@ LIBUNBOUND_AGE=1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# 1.26.2 had 9:41:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
@@ -25712,7 +25713,7 @@ printf "%s\n" "#define MAXSYSLOGMSGLEN 10240" >>confdefs.h
version=1.26.1
version=1.26.2
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for build time" >&5
printf %s "checking for build time... " >&6; }
@@ -26242,7 +26243,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
# report actual input values of CONFIG_FILES etc. instead of their
# values after options handling.
ac_log="
This file was extended by unbound $as_me 1.26.1, which was
This file was extended by unbound $as_me 1.26.2, which was
generated by GNU Autoconf 2.71. Invocation command line was
CONFIG_FILES = $CONFIG_FILES
@@ -26310,7 +26311,7 @@ ac_cs_config_escaped=`printf "%s\n" "$ac_cs_config" | sed "s/^ //; s/'/'\\\\\\\\
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
ac_cs_config='$ac_cs_config_escaped'
ac_cs_version="\\
unbound config.status 1.26.1
unbound config.status 1.26.2
configured by $0, generated by GNU Autoconf 2.71,
with options \\"\$ac_cs_config\\"
+3 -2
View File
@@ -12,14 +12,14 @@ sinclude(dnscrypt/dnscrypt.m4)
# must be numbers. ac_defun because of later processing
m4_define([VERSION_MAJOR],[1])
m4_define([VERSION_MINOR],[26])
m4_define([VERSION_MICRO],[1])
m4_define([VERSION_MICRO],[2])
AC_INIT([unbound],m4_defn([VERSION_MAJOR]).m4_defn([VERSION_MINOR]).m4_defn([VERSION_MICRO]),[unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues],[unbound])
AC_SUBST(UNBOUND_VERSION_MAJOR, [VERSION_MAJOR])
AC_SUBST(UNBOUND_VERSION_MINOR, [VERSION_MINOR])
AC_SUBST(UNBOUND_VERSION_MICRO, [VERSION_MICRO])
LIBUNBOUND_CURRENT=9
LIBUNBOUND_REVISION=40
LIBUNBOUND_REVISION=41
LIBUNBOUND_AGE=1
# 1.0.0 had 0:12:0
# 1.0.1 had 0:13:0
@@ -127,6 +127,7 @@ LIBUNBOUND_AGE=1
# 1.25.2 had 9:38:1
# 1.26.0 had 9:39:1
# 1.26.1 had 9:40:1
# 1.26.2 had 9:41:1
# Current -- the number of the binary API that we're implementing
# Revision -- which iteration of the implementation of the binary
+35
View File
@@ -1,3 +1,38 @@
16 September 2026: Wouter
- Release of 1.26.1 with the following security fixes.
- Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code
Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li
from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC
canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber,
for the report.
- Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption.
Thanks to Ben Morris from Anthropic for the report.
- Fix CVE-2026-77955, Possible ZONEMD verification bypass window.
Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
for the report. In addition, thanks to Qifan Zhang from Palo Alto
Networks for also reporting this issue.
- Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on
reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai
University, AOSP Lab for the report.
- Fix CVE-2026-80225, Possible degradation of service from continuous
queries on the same TCP/DoT connection. Thanks to Qifan Zhang from
Palo Alto Networks for the report.
- Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path.
Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
for the report.
- Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch
Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and
Xiang Li from Nankai University, AOSP Lab for the report. In
addition, thanks to Qifan Zhang from Palo Alto Networks for a
complimentary report.
- Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'.
Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the
University of Science and Technology of China (USTC) for the
report.
- The code repository continues with 1.26.2 under development,
that includes the changes from before the 1.26.1 commits.
15 September 2026: Wouter
- For #1507: TOCTOU race in store_rrsets() can return a
CNAME chain whose target owns no address.