SUSE-SU-2026:3885-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263885-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3885-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3885-1
Upstream
CVE (18)
Related
Published
2026-08-31T14:34:37Z
Modified
2026-09-10T18:23:42Z
Summary
Security update for unbound
Details

This update for unbound fixes the following issues:

Update to version 1.25.2.

Security issues fixed:

  • CVE-2026-40691: DoS due to heap overflow via single bad DNSCrypt query over TCP (bsc#1271875).
  • CVE-2026-42955: Ghost domain window can be extended by up to one cached TTL configured value for A/AAAA glue records (bsc#1271892).
  • CVE-2026-44621: Libunbound applications configured with unwanted-reply-threshold could eventually be abruptly terminated (bsc#1271876).
  • CVE-2026-44687: Off-by-one error in harden-below-nxdomain logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN (bsc#1271893).
  • CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels manipulation (bsc#1271877).
  • CVE-2026-46582: Replay of a wildcard rrset as another piece of data triggers poisoning in the server expired reply path (bsc#1271894).
  • CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out (bsc#1271882).
  • CVE-2026-50243: response-ip/rpz can rewrite BOGUS answers instead of returning SERVFAIL (bsc#1271880).
  • CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones (bsc#1271881).
  • CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush (bsc#1271883).
  • CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread (bsc#1271884).
  • CVE-2026-54478: DNS Cookie bypass when proxy-protocol with with answer-cookie:yes is used (bsc#1271895).
  • CVE-2026-55708: Privacy/configuration issue when adding local data in views through unbound-control (bsc#1271896).
  • CVE-2026-55717: serve-expired-client-timeout and response-ip CNAME redirect could lead to a crash (bsc#1271886).
  • CVE-2026-55990: Crash via crafted client UDP query due to DNSCrypt faulty configuration (bsc#1271887).
  • CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name (bsc#1271889).
  • CVE-2026-56444: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined in unusual configuration (bsc#1271890).

Other updates and bugfixes:

References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150600.23.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150600.23.19.1",
            "unbound-anchor":  "1.25.2-150600.23.19.1",
            "unbound-devel":  "1.25.2-150600.23.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3885-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150600.23.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "unbound":  "1.25.2-150600.23.19.1",
            "unbound-python":  "1.25.2-150600.23.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3885-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150600.23.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150600.23.19.1",
            "unbound-anchor":  "1.25.2-150600.23.19.1",
            "unbound-devel":  "1.25.2-150600.23.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3885-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
unbound

Package

Name
unbound
Purl
pkg:rpm/suse/unbound&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.2-150600.23.19.1

Ecosystem specific

{
    "binaries":  [
        {
            "libunbound8":  "1.25.2-150600.23.19.1",
            "unbound-anchor":  "1.25.2-150600.23.19.1",
            "unbound-devel":  "1.25.2-150600.23.19.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3885-1.json"