W.C.A. Wijngaards
914dbfea4e
- iana portlist update.
2026-07-22 14:12:34 +02:00
W.C.A. Wijngaards
cf5e6e89a5
- Fix error in log printout in fix for CVE-2026-50248, when the
...
primary name is bogus.
2026-07-22 12:16:49 +02:00
W.C.A. Wijngaards
4941edf275
- Unit test for CVE-2026-56416.
2026-07-22 12:06:00 +02:00
W.C.A. Wijngaards
b08723ef97
- Unit test for CVE-2026-55973.
2026-07-22 12:04:35 +02:00
W.C.A. Wijngaards
c163fbc505
- Unit test for CVE-2026-55717.
2026-07-22 12:03:48 +02:00
W.C.A. Wijngaards
eed3f1ab38
- Unit test for CVE-2026-50248.
2026-07-22 12:00:19 +02:00
W.C.A. Wijngaards
63501f51bb
- Unit test for CVE-2026-50243.
2026-07-22 11:59:36 +02:00
W.C.A. Wijngaards
1ae2570bda
- Unit test for CVE-2026-46582.
2026-07-22 11:58:18 +02:00
W.C.A. Wijngaards
9ad825b267
- Unit test for CVE-2026-50045.
2026-07-22 11:57:13 +02:00
W.C.A. Wijngaards
3d5e6c0692
- Unit test for CVE-2026-44690.
2026-07-22 11:56:08 +02:00
W.C.A. Wijngaards
23e19ca6fc
- Unit test for CVE-2026-44687.
2026-07-22 11:55:09 +02:00
W.C.A. Wijngaards
9f757aa9f3
- Unit test for CVE-2026-42955.
2026-07-22 11:54:00 +02:00
W.C.A. Wijngaards
1df6c170ff
Changelog entry for 1.25.2.
...
- Set the repository to 1.25.3, it continues with the previous
changes.
2026-07-22 11:38:48 +02:00
W.C.A. Wijngaards
7a95bedc26
Fix conflict merge fixup.
2026-07-22 11:36:06 +02:00
W.C.A. Wijngaards
ae685bc33d
Move repo to version 1.25.3.
2026-07-22 11:34:48 +02:00
W.C.A. Wijngaards
91ac449bcd
Merge branch 'branch-1.25.2'
2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards
c33ad1b1a2
rerun autoconf.
release-1.25.2
2026-07-22 10:21:21 +02:00
W.C.A. Wijngaards
84d9682dd0
- Fix CVE-2026-56444, Degradation of resolution service when
...
'discard-timeout' and 'serve-expired-client-timeout' are combined in
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
and Jiajia Liu, Northwestern Polytechnical University, for also
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
2026-07-22 10:19:50 +02:00
W.C.A. Wijngaards
4b1635e194
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
...
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
2026-07-22 10:19:28 +02:00
W.C.A. Wijngaards
aac261cbb3
- Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
...
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
Networks, for the report. In addition, thanks to Xuanchao Xie,
for also reporting this issue.
2026-07-22 10:19:02 +02:00
W.C.A. Wijngaards
ae1b3810cc
- Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
...
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:41 +02:00
W.C.A. Wijngaards
96f8755520
- Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
...
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:16 +02:00
W.C.A. Wijngaards
2ce2ca3691
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
...
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
2026-07-22 10:17:32 +02:00
W.C.A. Wijngaards
c29ff70f6a
- Fix CVE-2026-55708, Privacy/configuration issue when adding local
...
data in views through 'unbound-control'. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
2026-07-22 10:17:10 +02:00
W.C.A. Wijngaards
8a15ffee62
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
...
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:16:42 +02:00
W.C.A. Wijngaards
8c702de175
- Fix CVE-2026-52863, Memory corruption could lead to crash and
...
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:16:03 +02:00
W.C.A. Wijngaards
804cff4c15
- Fix CVE-2026-50252, Possible cache poisoning attack by mapping
...
source port population per thread. Thanks to Inbal Schussheim and
Amit Klein, Hebrew University, for the report.
2026-07-22 10:15:31 +02:00
W.C.A. Wijngaards
e180b06298
- Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers
...
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-22 10:15:02 +02:00
W.C.A. Wijngaards
3530c81e29
- Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
...
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:14:35 +02:00
W.C.A. Wijngaards
02b16de1ae
- Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
...
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-22 10:14:04 +02:00
W.C.A. Wijngaards
1ad8d4c395
- Fix CVE-2026-50046, Possible heap use-after-free in an error path
...
when a DoT forwarded query is jostled out. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
2026-07-22 10:13:36 +02:00
W.C.A. Wijngaards
364ac737f7
- Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation
...
restarts. Thanks to Kunjie Shang, University of Science and
Technology of China, for the report.
2026-07-22 10:13:14 +02:00
W.C.A. Wijngaards
f7637a4f18
- Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via
...
RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-22 10:12:38 +02:00
W.C.A. Wijngaards
1e1940383a
- Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain'
...
logic can shadow a stub/forward zone by a legitimate parent's
NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:12:03 +02:00
W.C.A. Wijngaards
f52a9e864b
- Fix CVE-2026-44621, Libunbound applications configured with
...
'unwanted-reply-threshold' could eventually be abruptly
terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
2026-07-22 10:11:26 +02:00
W.C.A. Wijngaards
13ec8d0f26
- Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp
...
the TTL of A/AAAA records disallowing a one-time 'ghost domain'
delegation renewal via glue records. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
2026-07-22 10:11:04 +02:00
W.C.A. Wijngaards
27f22b8808
- Fix CVE-2026-41637, Degradation of resolution service from
...
improperly accounted client-terminated DNS-over-QUIC queries. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:10:24 +02:00
W.C.A. Wijngaards
f54e0791ba
- Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks
...
to Qifan Zhang, Palo Alto Networks, for the report. In addition,
thanks to Trung Nguyen (@everping) of CyStack, for also reporting
this issue.
2026-07-22 10:09:50 +02:00
W.C.A. Wijngaards
01dfd2f466
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
...
service due to `quic-size` budget bypass. Thanks to N0zoM1z0
(https://github.com/N0zoM1z0 ) for the report. In addition, thanks to
Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for also reporting this issue. In addition, thanks to Qifan Zhang,
Palo Alto Networks, for also reporting this issue. In addition,
thanks to Xuanchao Xie, for also reporting this issue.
2026-07-22 10:09:26 +02:00
W.C.A. Wijngaards
f157c691bb
- Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure
...
in high concurrency DNS-over-QUIC environments. Thanks to Kunta
Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
for the report.
2026-07-22 10:08:48 +02:00
W.C.A. Wijngaards
fea0ff550b
- Fix CVE-2026-46582, A wildcard replay, as another piece of data,
...
triggers poisoning in the serve expired reply path. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:07:52 +02:00
W.C.A. Wijngaards
87d59bfced
Set version to 1.25.2
2026-07-22 10:06:30 +02:00
W.C.A. Wijngaards
25b2543e5e
Changelog note for #1476
...
- Merge #1476 from petrvaganoff: ipsecmod: fix possible deref
on null after reply_find_answer_rrset().
2026-07-21 11:57:14 +02:00
Petr Vaganov and GitHub
7133e0d32a
ipsecmod: fix possible deref on null after reply_find_answer_rrset() ( #1476 )
...
Return value of a function 'reply_find_answer_rrset' is dereferenced at
ipsecmod.c:438 without checking for NULL, but it is usually checked for
this function (10/12).
Found by the static analyzer Svace (ISP RAS).
Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com >
2026-07-21 11:56:29 +02:00
W.C.A. Wijngaards
fac7584830
- Fix #1474 : DoQ responses are never padded - pad-responses
...
does not apply to comm_doq (RFC 9250 §5.4 MUST).
2026-07-20 10:14:26 +02:00
W.C.A. Wijngaards
87f9258fb4
Changelog entry for #1475
...
- Merge #1475 from petrvaganoff: ipsecmod: fix deref on null
in ipsecmod-whitelist after OOM.
2026-07-20 10:05:45 +02:00
Petr Vaganov and GitHub
a2fe5356b5
ipsecmod: fix deref on null in ipsecmod-whitelist after OOM ( #1475 )
...
DEREF_OF_NULL.RET.STAT Return value of a function 'rbtree_create'
is dereferenced at ipsecmod-whitelist.c:105 without checking for
NULL, but it is usually checked for this function (5/6).
In ipsecmod_whitelist_apply_cfg(), the return value of rbtree_create()
is not checked for NULL before being used.
Found by the static analyzer Svace (ISP RAS).
Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com >
2026-07-20 10:04:47 +02:00
W.C.A. Wijngaards
ad9b12a863
- Fix unit test for malformed svcb for test on Windows.
2026-07-09 09:52:09 +02:00
W.C.A. Wijngaards
61ca4111a1
Changelog note and explanation comment for #1383
...
- Merge #1383 from jdek: Fix randomness generation on
macOS/iOS under chroot.
2026-07-09 09:21:56 +02:00
J. Dekker and GitHub
71a971d70c
- Fix randomness generation on macOS/iOS under chroot ( #1383 )
...
SecRandomCopyBytes() has existed since macOS 10.7 (2011) and iOS 2.0 (2008), and is the primary API for cryptographic random numbers.
2026-07-09 09:19:42 +02:00