UbuntuUpdates.org

Package "unbound"

Name: unbound

Description:

validating, recursive, caching DNS resolver

Latest version: 1.13.1-1ubuntu5.13
Release: jammy (22.04)
Level: updates
Repository: universe
Homepage: https://www.unbound.net/

Links


Download "unbound"


Other versions of "unbound" in Jammy

Repository Area Version
base main 1.13.1-1ubuntu5
base universe 1.13.1-1ubuntu5
security main 1.13.1-1ubuntu5.13
security universe 1.13.1-1ubuntu5.13
updates main 1.13.1-1ubuntu5.13

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.13.1-1ubuntu5.13 2025-11-04 22:07:10 UTC

  unbound (1.13.1-1ubuntu5.13) jammy-security; urgency=medium

  * SECURITY UPDATE: promiscuous NS RRSets domain hijack issue
    - debian/patches/CVE-2025-11411.patch: fix possible domain hijacking
      attack and add new iter-scrub-promiscuous configuration option.
    - CVE-2025-11411

 -- Marc Deslauriers <email address hidden> Fri, 31 Oct 2025 09:39:13 -0400

Source diff to previous version
CVE-2025-11411 NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive

Version: 1.13.1-1ubuntu5.12 2025-10-09 02:07:21 UTC

  unbound (1.13.1-1ubuntu5.12) jammy; urgency=medium

  * Update MAX_RESTART_COUNT from 8 to 11 to allow longer CNAME chains
    (LP: #2122609)

 -- Bryan Alexander <email address hidden> Fri, 26 Sep 2025 12:08:24 -0700

Source diff to previous version
2122609 Hardcoded MAX_RESTART_COUNT in unbound 1.13.1 blocks dns resolution of long cname chains

Version: 1.13.1-1ubuntu5.11 2025-07-22 22:06:50 UTC

  unbound (1.13.1-1ubuntu5.11) jammy-security; urgency=medium

  * SECURITY UPDATE: Rebirthday Attack cache poisoning issue
    - debian/patches/CVE-2025-5994.patch: Fix issue in
      edns-subnet/subnetmod.c, edns-subnet/subnetmod.h.
    - CVE-2025-5994

 -- Marc Deslauriers <email address hidden> Fri, 18 Jul 2025 13:40:33 -0400

Source diff to previous version
CVE-2025-5994 A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS)

Version: 1.13.1-1ubuntu5.10 2025-04-17 00:07:13 UTC

  unbound (1.13.1-1ubuntu5.10) jammy; urgency=medium

  * d/p/lp-2087526-1-fix-memory-exhaust-in-local-zones.patch:
    fix error: fix contents_view ordering in patch (LP: #2087526)

Source diff to previous version
2087526 unbound cannot start with large zone files \u003e 24.000 lines : memory exhausted

Version: 1.13.1-1ubuntu5.8 2024-10-22 14:07:14 UTC

  unbound (1.13.1-1ubuntu5.8) jammy-security; urgency=medium

  * SECURITY UPDATE: denial of service via large RRsets compression
    - debian/patches/CVE-2024-8508.patch: limit name compression
      calculations per packet to avoid CPU lockup in util/data/msgencode.c
    - CVE-2024-8508

 -- Vyom Yadav <email address hidden> Thu, 17 Oct 2024 11:28:18 +0530

CVE-2024-8508 NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform



About   -   Send Feedback to @ubuntu_updates