UbuntuUpdates.org

Package "unbound"

Name: unbound

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • static library, header files, and docs for libunbound
  • library implementing DNS resolution and validation

Latest version: 1.19.2-1ubuntu3.7
Release: noble (24.04)
Level: updates
Repository: main

Links



Other versions of "unbound" in Noble

Repository Area Version
base universe 1.19.2-1ubuntu3
base main 1.19.2-1ubuntu3
security main 1.19.2-1ubuntu3.7
security universe 1.19.2-1ubuntu3.7
updates universe 1.19.2-1ubuntu3.7

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.19.2-1ubuntu3.7 2025-12-02 19:08:34 UTC

  unbound (1.19.2-1ubuntu3.7) noble-security; urgency=medium

  * SECURITY REGRESSION: Incomplete fix for CVE-2025-11411.
    - debian/patches/CVE-2025-11411-fix1.patch: Add mitigations for YXDOMAIN in
      iterator/iter_scrub.c. Add tests in testdata/iter_scrub_promiscuous.rpl
      and testdata/ratelimit.tdir/ratelimit.testns.
    - CVE-2025-11411

 -- Hlib Korzhynskyy <email address hidden> Mon, 01 Dec 2025 14:03:30 -0330

Source diff to previous version
CVE-2025-11411 NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive

Version: 1.19.2-1ubuntu3.6 2025-11-05 03:07:05 UTC

  unbound (1.19.2-1ubuntu3.6) noble-security; urgency=medium

  * SECURITY UPDATE: promiscuous NS RRSets domain hijack issue
    - debian/patches/CVE-2025-11411.patch: fix possible domain hijacking
      attack and add new iter-scrub-promiscuous configuration option.
    - CVE-2025-11411

 -- Marc Deslauriers <email address hidden> Fri, 31 Oct 2025 09:21:18 -0400

Source diff to previous version
CVE-2025-11411 NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive

Version: 1.19.2-1ubuntu3.5 2025-07-22 22:06:52 UTC

  unbound (1.19.2-1ubuntu3.5) noble-security; urgency=medium

  * SECURITY UPDATE: Rebirthday Attack cache poisoning issue
    - debian/patches/CVE-2025-5994.patch: Fix issue in
      edns-subnet/subnetmod.c, edns-subnet/subnetmod.h.
    - CVE-2025-5994

 -- Marc Deslauriers <email address hidden> Fri, 18 Jul 2025 13:32:04 -0400

Source diff to previous version
CVE-2025-5994 A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS)

Version: 1.19.2-1ubuntu3.4 2025-03-17 12:07:02 UTC

  unbound (1.19.2-1ubuntu3.4) noble; urgency=medium

  * debian/patches/lp-2087526-1-fix-memory-exhaust-in-local-zones.patch:
    fix error: "memory exhausted" when defining more than 9994
    local_zones. (LP: #2087526).

 -- John Chittum <email address hidden> Thu, 06 Feb 2025 14:41:07 -0500

Source diff to previous version
2087526 unbound cannot start with large zone files \u003e 24.000 lines : memory exhausted

Version: 1.19.2-1ubuntu3.3 2024-10-22 14:07:14 UTC

  unbound (1.19.2-1ubuntu3.3) noble-security; urgency=medium

  * SECURITY UPDATE: denial of service via large RRsets compression
    - debian/patches/CVE-2024-8508.patch: limit name compression
      calculations per packet to avoid CPU lockup in util/data/msgencode.c
    - CVE-2024-8508

 -- Vyom Yadav <email address hidden> Thu, 17 Oct 2024 11:23:42 +0530

CVE-2024-8508 NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform



About   -   Send Feedback to @ubuntu_updates