SUSE-SU-2026:3884-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263884-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3884-1
Upstream
CVE (17)
Related
Published
2026-08-31T14:33:51Z
Modified
2026-09-10T18:23:42Z
Summary
Security update for unbound
Details

This update for unbound fixes the following issues:

Update to version 1.25.2.

Security issues fixed:

  • CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875).
  • CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records (bsc#1271892).
  • CVE-2026-44621: Libunbound applications configured with unwanted-reply-threshold could eventually be abruptly terminated (bsc#1271876).
  • CVE-2026-44687: Off-by-one error in harden-below-nxdomain logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN (bsc#1271893).
  • CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels manipulation (bsc#1271877).
  • CVE-2026-46582: Replay of a wildcard rrset as another piece of data triggers poisoning in the server expired reply path (bsc#1271894).
  • CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882).
  • CVE-2026-50243: response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).
  • CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881).
  • CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush (bsc#1271883).
  • CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884).
  • CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with answer-cookie:yes is used (bsc#1271895).
  • CVE-2026-55708: Privacy/configuration issue when adding local data in views through unbound-control (bsc#1271896).
  • CVE-2026-55717: serve-expired-client-timeout and response-ip CNAME redirect could lead to a crash (bsc#1271886).
  • CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887).
  • CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name (bsc#1271889).
  • CVE-2026-56444: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined in unusual configuration (bsc#1271890).

Other updates and bugfixes:

References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise Micro 5.5
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150100.10.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150100.10.28.1",
            "unbound-anchor":  "1.25.2-150100.10.28.1",
            "unbound-devel":  "1.25.2-150100.10.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3884-1.json"