SUSE-SU-2026:23360-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202623360-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23360-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:23360-1
Upstream
CVE (23)
Related
Published
2026-08-26T14:27:41Z
Modified
2026-09-10T18:23:37Z
Summary
Security update for unbound
Details

This update for unbound fixes the following issues:

Update to version 1.25.2.

Security issues fixed:

  • CVE-2026-14586: DoS via assertion in libngtcp2 for DNS-over-QUIC environments with high concurrency (bsc#1271879).
  • CVE-2026-32665: Remote DNS-over-QUIC denial of service due to quic-size budget bypass (bsc#1271873).
  • CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875).
  • CVE-2026-41637: Degradation of resolution service due to improperly accounted client-terminated DNS-over-QUIC queries (bsc#1271891).
  • CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records (bsc#1271892).
  • CVE-2026-44621: Libunbound applications configured with unwanted-reply-threshold could eventually be abruptly terminated (bsc#1271876).
  • CVE-2026-44687: Off-by-one error in harden-below-nxdomain logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN (bsc#1271893).
  • CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels manipulation (bsc#1271877).
  • CVE-2026-46582: Replay of a wildcard rrset as another piece of data triggers poisoning in the server expired reply path (bsc#1271894).
  • CVE-2026-50045: max-global-quota bypass via single client queries for a deeply nested name under a DNSSEC-signed parent (bsc#1271878).
  • CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882).
  • CVE-2026-50243: response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).
  • CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881).
  • CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush (bsc#1271883).
  • CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884).
  • CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with answer-cookie:yes is used (bsc#1271895).
  • CVE-2026-55708: Privacy/configuration issue when adding local data in views through unbound-control (bsc#1271896).
  • CVE-2026-55717: serve-expired-client-timeout and response-ip CNAME redirect could lead to a crash (bsc#1271886).
  • CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887).
  • CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control reacheable assertion failure in libngtcp2 (bsc#1271888).
  • CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name (bsc#1271889).
  • CVE-2026-56444: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined in unusual configuration (bsc#1271890).

Other updates and bugfixes:

References

Affected packages

SUSE:Linux Micro 6.0 / unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-1.1",
            "unbound-anchor":  "1.25.2-1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23360-1.json"