akhanin-dnsf and GitHub
307fc6f062
- Fix bounds check in packed_rr_to_string, it checked the ( #1488 )
...
assembled rr length against the output string length
dest_len, instead of against the size of the rr buffer it
writes into. Callers in cachedump.c and remote.c pass a
dest_len larger than that buffer.
- Unit test for packed_rr_to_string.
2026-08-06 17:04:05 +02:00
W.C.A. Wijngaards
91ac449bcd
Merge branch 'branch-1.25.2'
2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards
4b1635e194
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
...
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
2026-07-22 10:19:28 +02:00
W.C.A. Wijngaards
2ce2ca3691
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
...
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
2026-07-22 10:17:32 +02:00
W.C.A. Wijngaards
8a15ffee62
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
...
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:16:42 +02:00
W.C.A. Wijngaards
fac7584830
- Fix #1474 : DoQ responses are never padded - pad-responses
...
does not apply to comm_doq (RFC 9250 §5.4 MUST).
2026-07-20 10:14:26 +02:00
W.C.A. Wijngaards
215e3920ef
- Fix that after malloc failure in find_tag_datas, the
...
local_alias is cleaned up. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
2026-06-16 10:51:49 +02:00
W.C.A. Wijngaards
8557788699
- Fix that after malloc failure a half-built local_alias does
...
not crash the server. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-06-16 10:12:19 +02:00
W.C.A. Wijngaards
f68cca4097
- Fix DNAME synthesis from cache that keeps use of 0TTL
...
entries in a sliding window. It did not surpass RRSIG
expiry. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
2026-06-15 16:39:34 +02:00
W.C.A. Wijngaards
b1d1dcb3b6
- Fix that dump_cache has a larger buffer for records,
...
and it checks that an owner name does not collide with BADRR
on the input, and changes verbosity on the log of failure in
rrset to string. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-06-03 14:51:16 +02:00
W.C.A. Wijngaards
fbbe95ba5b
- Fix that msgencode insert_query has the correct assertion,
...
for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-05-27 12:20:04 +02:00
W.C.A. Wijngaards
3692517a41
Merge branch 'branch-1.25.1'
2026-05-20 11:19:56 +02:00
W.C.A. Wijngaards
dae7a37974
- Fix CVE-2026-44390, Unbounded name compression in certain cases
...
causes degradation of service. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-05-20 10:21:26 +02:00
W.C.A. Wijngaards
ef5ca84360
- Fix CVE-2026-41292, Parsing a long list of incoming EDNS options
...
degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan
Zhang from Palo Alto Networks, for the report.
2026-05-20 10:18:23 +02:00
W.C.A. Wijngaards
fe946ba4e9
- Fix CVE-2026-42944, Heap overflow and crash with multiple nsid,
...
cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-05-20 10:13:55 +02:00
W.C.A. Wijngaards
8ada1bd88d
- Fix to relax assertions after the TTL 0 handling change.
...
This relaxes an assertion in cachedb (it fails instead),
and for packet_rrset_copy_region.
2026-05-08 10:09:41 +02:00
W.C.A. Wijngaards
84ac7e1b58
- Fix ttl comparisons in rdata_copy for 32bit signed or unsigned.
2026-04-17 13:27:41 +02:00
W.C.A. Wijngaards
a296b248b0
- For #1411 : Fix that the lookup for DNAME uses flag. Fix assertion
...
in expired calc debug routine.
2026-03-03 17:44:31 +01:00
nnarayanamurthy and GitHub
fe10bc7682
QNX Porting support for unbound branch-1.24.1 ( #1388 )
...
* qnx Porting support for version release-1.24.1
* updating __QNXNTO__ with __QNX__
2026-01-21 13:12:13 +01:00
Yorgos Thessalonikefs
44659cb3bf
- Use the same EDE removal logic when encoding errors as when encoding
...
replies.
2025-12-31 16:22:15 +01:00
Yorgos Thessalonikefs
35f6fd47fb
- Test for nonstring attribute in configure and add
...
nonstring attribute annotations.
2025-09-26 16:23:55 +02:00
Yorgos Thessalonikefs
e2bf773089
Merge branch 'features/no-ttl-zero-cacherep'
2025-09-19 14:56:04 +02:00
bc61034f60
code review: use proper roundrobin index
...
Co-authored-by: Wouter Wijngaards <wcawijngaards@users.noreply.github.com >
2025-09-17 12:19:20 +02:00
Yorgos Thessalonikefs
2dd821c257
- Too many quotes for the EDE message debug printout.
2025-09-17 11:27:16 +02:00
Yorgos Thessalonikefs
c3a8d5251f
- Small debug output improvement when attaching an EDE.
2025-09-15 12:06:49 +02:00
Yorgos Thessalonikefs
73e408f1d0
A few changes for TTL processing:
...
- Cached messages that reach 0 TTL are considered expired. This prevents
Unbound itself from issuing replies with TTL 0 and possibly causing a
thundering herd at the last second. Upstream replies of TTL 0 still
get the usual pass-through but they are not considered for caching
from Unbound or any of its caching modules.
- 'serve-expired-reply-ttl' is changed and is now capped by the original
TTL value of the record to try and make some sense when replying
with expired records.
- TTL decoding was updated to adhere to RFC8767 section 4 where a set
high-order bit means the value is positive instead of 0.
2025-09-15 10:03:35 +02:00
Yorgos Thessalonikefs
d521135f66
Merge branch 'master' into features/no-ttl-zero-cacherep
2025-09-12 15:24:06 +02:00
W.C.A. Wijngaards
752a3f7f52
- Fix to whitespace in dname_str.
2025-08-07 16:19:10 +02:00
W.C.A. Wijngaards
08d59c9a78
- Fix dname_str for printout of long names. Thanks to Jan Komissar
...
for the fix.
2025-08-07 09:45:02 +02:00
Jose Luis Duran and GitHub
41c55ffac1
Fix typos ( #1299 )
2025-07-02 10:50:49 +02:00
Yorgos Thessalonikefs
9201c75013
- Fix for consistent use of local zone CNAME alias for configured auth
...
zones. Now it also applies to downstream configured auth zones.
2025-06-17 15:03:29 +02:00
W.C.A. Wijngaards
e4cf7aeccf
- Fix header return value description for skip_pkt_rrs and
...
parse_edns_from_query_pkt.
2025-06-12 12:17:01 +02:00
W.C.A. Wijngaards
a8aa1dbbe1
- Fix conditional expressions with parentheses for bitwise and.
2025-06-11 16:42:43 +02:00
W.C.A. Wijngaards
565bce670c
- Fix comment for the dname_remove_label_limit_len function.
2025-06-05 11:11:32 +02:00
Yorgos Thessalonikefs
9152c914af
- Fix #1282 : log-destaddr fail on long ipv6 addresses.
2025-05-13 11:02:58 +02:00
Yorgos Thessalonikefs and GitHub
4e23523d1a
Fix auth nsec3 code ( #1280 )
...
- Fix NSEC3 code to not break on broken auth zones that include unsigned
out of zone (above apex) data. Could lead to hang while trying to
prove a wildcard answer.
Reported by Dmitrii Kuvaiskii from Amazon Web Services.
- Tests for NSEC3 auth zones with out of zone data.
2025-05-12 14:26:47 +02:00
W.C.A. Wijngaards
16ee7cf944
- Fix for print of connection type in log-replies for dot and doh.
2025-04-10 09:33:51 +02:00
Yorgos Thessalonikefs
9de159b96b
- For #1175 , the default value of serve-expired-ttl is set to 86400
...
(1 day) as suggested by RFC8767.
2024-12-03 13:09:51 +01:00
Yorgos Thessalonikefs
f46acec35f
- For #1189 , homogenize the input buffer size for dname_str().
2024-12-02 11:53:56 +01:00
Yorgos Thessalonikefs
1cd2fb3b9d
- For #1189 , add unit tests for dname_str() and debug check the input
...
buffer size.
2024-12-02 10:03:35 +01:00
wenxuan70
06fb30d0a0
Fix the dname_str method to cause conversion errors when the domain name length is 255
2024-11-24 17:53:23 +08:00
W.C.A. Wijngaards
50fcf71f04
- ttl-zero-cacherep, Responses in the last second of their cache TTL,
...
get an extra second. That makes the TTL not 0, since they are from
cache and can be cached by the client.
2024-11-11 15:43:10 +01:00
Yorgos Thessalonikefs
490585bf29
Merge branch 'release-1.21.1'
2024-10-03 18:14:01 +02:00
Yorgos Thessalonikefs
b7c61d7cc2
- Fix CVE-2024-8508, unbounded name compression could lead to denial of
...
service.
2024-10-03 17:41:20 +02:00
Yorgos Thessalonikefs and GitHub
2e398d51ba
Fix cache update when serve expired is used ( #1143 )
...
- Fix cache update when serve expired is used in order to not evict
still usable expired records. Modules are forbidden to update the
cache if their answer is DNSSEC unchecked or bogus and a valid
(expired) entry already exists. Bogus replies from the validator are
also discarded in favor of existing (expired) valid replies.
- serve-expired-ttl-reset should try to keep expired records in the
cache in case they are reset.
2024-09-24 16:47:04 +02:00
W.C.A. Wijngaards
1e0cf1e86b
- Merge patch to fix for glue that is outside of zone, with
...
`harden-unverified-glue`, from Karthik Umashankar (Microsoft).
Enabling this option protects the Unbound resolver against bad
glue, that is unverified out of zone glue, by resolving them.
It uses the records as last resort if there is no other working
glue.
2024-08-23 08:56:48 +02:00
ad21dbd1c2
Cookie secret file ( #1090 )
...
* - cookie-secret-file, define struct.
* - cookie-secret-file, add config option, create, read and delete struct.
* - cookie-secret-file, check cookie secrets for cookie validation.
* - cookie-secret-file, unbound-control add_cookie_secret, drop_cookie_secret,
activate_cookie_secret and print_cookie_secrets.
* - cookie-secret-file, test and fix locks, renew writes a fresh cookie,
staging cookies get a fresh cookie and spelling in error message.
* - cookie-secret-file, remove unused variable from cookie file unit test.
* Remove unshare and faketime dependencies for cookie_file test; documentation nits.
---------
Co-authored-by: Yorgos Thessalonikefs <yorgos@nlnetlabs.nl >
2024-08-02 13:32:08 +02:00
W.C.A. Wijngaards
5bea29b01c
- For #1110 : Test for fallthrough attribute in configure and add
...
fallthrough attribute annotations.
2024-07-23 09:47:42 +02:00
Yorgos Thessalonikefs and GitHub
6f030e9672
Proper parent identification for dynamically entered local zones ( #1076 )
...
- Fix #1059 : Intermittent DNS blocking failure with local-zone and
always_nxdomain. Addition of local_zones dynamically via
unbound-control was not finding the zone's parent correctly.
2024-05-24 15:21:40 +02:00
Yorgos Thessalonikefs
025881d0e9
- Introduce 'cache-min-negative-ttl' option to bound the minimum TTL for
...
negative answers overriding 'cache-min-ttl'.
2024-03-12 11:24:59 +01:00