This update for unbound fixes the following issues:
Update to version 1.25.2.
Security issues fixed:
libngtcp2 for DNS-over-QUIC environments with high concurrency (bsc#1271879).quic-size budget bypass (bsc#1271873).unwanted-reply-threshold could eventually be abruptly
terminated (bsc#1271876).harden-below-nxdomain logic can shadow a stub/forward zone by a legitimate
parent's NXDOMAIN (bsc#1271893).RRSIG.labels manipulation (bsc#1271877).rrset as another piece of data triggers poisoning in the server expired reply
path (bsc#1271894).max-global-quota bypass via single client queries for a deeply nested name under a DNSSEC-signed
parent (bsc#1271878).response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).0.0.0.0/:: glue triggers defensive full-cache flush (bsc#1271883).answer-cookie:yes is used (bsc#1271895).unbound-control (bsc#1271896).serve-expired-client-timeout and response-ip CNAME redirect could lead to a crash (bsc#1271886).libngtcp2 (bsc#1271888).discard-timeout and serve-expired-client-timeout are
combined in unusual configuration (bsc#1271890).Other updates and bugfixes:
unbound.keyring.