W.C.A. Wijngaards
9bd8df0149
- Fix to use tls-port after referral if tls-upstream is set.
2026-07-24 15:31:06 +02:00
W.C.A. Wijngaards
8f7411057f
- Fix sign of comparison warning in shared ports setup.
2026-07-24 14:44:44 +02:00
W.C.A. Wijngaards
ca1fe4f82a
- Fix to guard access to shared ports interface array during
...
set up, for analyzer.
2026-07-24 14:38:46 +02:00
W.C.A. Wijngaards
e183c2c506
- Fix unused variable warnings in shared_ports_fetch_random
...
and shared_ports_return_port when compiled without threads.
2026-07-24 14:37:17 +02:00
W.C.A. Wijngaards
52b18fc6f5
Changelog entry for #1480
...
- Merge #1480 from petrvaganoff: authzone: fix memory leak in
xfer_set_masters() error path.
2026-07-24 12:25:34 +02:00
Petr Vaganov and GitHub
e6d00725c2
authzone: fix memory leak in xfer_set_masters() error path ( #1480 )
...
Added memory deallocation for the `file` and `host` fields of the
`auth_master` node in the event of a URL/allocation error, and
unlinked the partially created node from the masters list by
resetting the link that pointed to it.
Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com >
2026-07-24 12:24:49 +02:00
W.C.A. Wijngaards
e597711824
- Fix lock test protect for auth zone change.
...
- Fix to lock shared_ports structure during initialisation.
- Fix to lock anchor structure when file is set for it in
2026-07-24 12:13:09 +02:00
W.C.A. Wijngaards
e1e646c6fc
- Fix to allow test fake sha1 on systems with possible sha1
...
support.
- Fix to use sha256 for unbound-anchor unit test.
- Fix unbound-anchor check for return value of
X509_NAME_get_text_by_NID of the emailaddress.
2026-07-24 11:50:15 +02:00
W.C.A. Wijngaards
fc3b5b4f63
- Update generated man pages.
2026-07-24 10:03:41 +02:00
W.C.A. Wijngaards
1e904a3ce5
- set code repository version to 1.26.0.
2026-07-24 09:45:49 +02:00
W.C.A. Wijngaards
79e100a7fb
- Fix #1477 : respip + dns64: dns64 uses A records modified by
...
respip instead of original A records. Adds local-zone types
block_a_wdata and block_aaaa_wdata, that are like block_a
and block_aaaa, and uses local-data if present.
2026-07-24 09:29:17 +02:00
W.C.A. Wijngaards
a65d3d7283
- Unit test for block_a and block_aaaa.
2026-07-24 09:03:45 +02:00
W.C.A. Wijngaards
3b8766aa43
Changelog note for #1433
...
- Merge #1433 from jisakiel: Add new static zone type
block_aaaa to suppress AAAA queries.
2026-07-24 08:53:30 +02:00
c8b3c89a39
Add new static zone type block_aaaa to suppress AAAA queries ( #1433 )
...
Following d5b9a790f lead for block_a - this would allow suppressing AAAA queries instead for sticking to IPV4.
Co-authored-by: Jisakiel <jisakiel@users.noreply.github.com >
2026-07-24 08:52:20 +02:00
W.C.A. Wijngaards
a05d460e66
- Fix mesh cycle detection for configuration with respip CNAME
...
loop and tagged clients. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-23 16:28:45 +02:00
W.C.A. Wijngaards
5eb362a6c0
- Fix that the aggressive negative cache does not insert NSEC
...
records with overreaching next owner name. Also the result
is not above the trust anchor's bailiwick. Also RRSIGS are
not considered valid when an NSEC next owner name is not
under the signer zone name. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
2026-07-23 16:17:59 +02:00
W.C.A. Wijngaards
0735cb28d1
- Fix that for NSEC3 proofs the NSEC3 zone, as the b32.name is
...
checked to be the same as the signer name. Also RRSIGs are
not considered valid when an NSEC3 is not b32.signerzone.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-23 15:54:59 +02:00
W.C.A. Wijngaards
737c28e836
Changelog entry for #1478
...
- Merge #1478 from petrvaganoff: pythonmod: add check return
value after ftell().
2026-07-23 10:22:53 +02:00
Petr Vaganov and GitHub
1bab2dfafa
pythonmod: add check return value after ftell() ( #1478 )
...
Variable 'flen', which might receive a negative value at pythonmod.c:493
by calling function 'ftell', is used without checking at pythonmod.c:508
by calling function 'fread'.
Found by the static analyzer Svace (ISP RAS).
Signed-off-by: Petr Vaganov <petrvaganoff@gmail.com >
2026-07-23 10:22:02 +02:00
W.C.A. Wijngaards
22e2c5b6d1
- Updated credits for Xuanchao Xie in 22 july changelog.
2026-07-23 10:01:10 +02:00
W.C.A. Wijngaards
914dbfea4e
- iana portlist update.
2026-07-22 14:12:34 +02:00
W.C.A. Wijngaards
cf5e6e89a5
- Fix error in log printout in fix for CVE-2026-50248, when the
...
primary name is bogus.
2026-07-22 12:16:49 +02:00
W.C.A. Wijngaards
4941edf275
- Unit test for CVE-2026-56416.
2026-07-22 12:06:00 +02:00
W.C.A. Wijngaards
b08723ef97
- Unit test for CVE-2026-55973.
2026-07-22 12:04:35 +02:00
W.C.A. Wijngaards
c163fbc505
- Unit test for CVE-2026-55717.
2026-07-22 12:03:48 +02:00
W.C.A. Wijngaards
eed3f1ab38
- Unit test for CVE-2026-50248.
2026-07-22 12:00:19 +02:00
W.C.A. Wijngaards
63501f51bb
- Unit test for CVE-2026-50243.
2026-07-22 11:59:36 +02:00
W.C.A. Wijngaards
1ae2570bda
- Unit test for CVE-2026-46582.
2026-07-22 11:58:18 +02:00
W.C.A. Wijngaards
9ad825b267
- Unit test for CVE-2026-50045.
2026-07-22 11:57:13 +02:00
W.C.A. Wijngaards
3d5e6c0692
- Unit test for CVE-2026-44690.
2026-07-22 11:56:08 +02:00
W.C.A. Wijngaards
23e19ca6fc
- Unit test for CVE-2026-44687.
2026-07-22 11:55:09 +02:00
W.C.A. Wijngaards
9f757aa9f3
- Unit test for CVE-2026-42955.
2026-07-22 11:54:00 +02:00
W.C.A. Wijngaards
1df6c170ff
Changelog entry for 1.25.2.
...
- Set the repository to 1.25.3, it continues with the previous
changes.
2026-07-22 11:38:48 +02:00
W.C.A. Wijngaards
7a95bedc26
Fix conflict merge fixup.
2026-07-22 11:36:06 +02:00
W.C.A. Wijngaards
ae685bc33d
Move repo to version 1.25.3.
2026-07-22 11:34:48 +02:00
W.C.A. Wijngaards
91ac449bcd
Merge branch 'branch-1.25.2'
2026-07-22 11:33:54 +02:00
W.C.A. Wijngaards
c33ad1b1a2
rerun autoconf.
release-1.25.2
2026-07-22 10:21:21 +02:00
W.C.A. Wijngaards
84d9682dd0
- Fix CVE-2026-56444, Degradation of resolution service when
...
'discard-timeout' and 'serve-expired-client-timeout' are combined in
unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks,
for the report. In addition, thanks to Xin Wang, Jiapeng Li,
and Jiajia Liu, Northwestern Polytechnical University, for also
reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
2026-07-22 10:19:50 +02:00
W.C.A. Wijngaards
4b1635e194
- Fix CVE-2026-56416, Possible heap buffer overflow when validator
...
canonicalizes RDATA that contains domain name. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
2026-07-22 10:19:28 +02:00
W.C.A. Wijngaards
aac261cbb3
- Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control
...
assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto
Networks, for the report. In addition, thanks to Xuanchao Xie,
for also reporting this issue.
2026-07-22 10:19:02 +02:00
W.C.A. Wijngaards
ae1b3810cc
- Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured
...
Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:41 +02:00
W.C.A. Wijngaards
96f8755520
- Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer
...
overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
2026-07-22 10:18:16 +02:00
W.C.A. Wijngaards
2ce2ca3691
- Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip'
...
CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo
Alto Networks, for the report. In addition, thanks to Xin Wang,
Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University,
for also reporting this issue.
2026-07-22 10:17:32 +02:00
W.C.A. Wijngaards
c29ff70f6a
- Fix CVE-2026-55708, Privacy/configuration issue when adding local
...
data in views through 'unbound-control'. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
2026-07-22 10:17:10 +02:00
W.C.A. Wijngaards
8a15ffee62
- Fix CVE-2026-54478, DNS Cookie bypass when combined with
...
proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:16:42 +02:00
W.C.A. Wijngaards
8c702de175
- Fix CVE-2026-52863, Memory corruption could lead to crash and
...
denial of service. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:16:03 +02:00
W.C.A. Wijngaards
804cff4c15
- Fix CVE-2026-50252, Possible cache poisoning attack by mapping
...
source port population per thread. Thanks to Inbal Schussheim and
Amit Klein, Hebrew University, for the report.
2026-07-22 10:15:31 +02:00
W.C.A. Wijngaards
e180b06298
- Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers
...
defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-22 10:15:02 +02:00
W.C.A. Wijngaards
3530c81e29
- Fix CVE-2026-50248, BOGUS configured primary hostname accepted for
...
XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks,
for the report.
2026-07-22 10:14:35 +02:00
W.C.A. Wijngaards
02b16de1ae
- Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers
...
instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
2026-07-22 10:14:04 +02:00