Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package unbound for openSUSE:Factory checked in at 2026-07-26 11:27:47 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/unbound (Old) and /work/SRC/openSUSE:Factory/.unbound.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "unbound" Sun Jul 26 11:27:47 2026 rev:83 rq:1367379 version:1.25.2 Changes: -------- --- /work/SRC/openSUSE:Factory/unbound/libunbound-devel-mini.changes 2026-05-29 18:04:21.731545483 +0200 +++ /work/SRC/openSUSE:Factory/.unbound.new.2004/libunbound-devel-mini.changes 2026-07-26 11:29:52.941607641 +0200 @@ -1,0 +2,80 @@ +Thu Jul 23 10:10:09 UTC 2026 - Jorik Cronenberg <[email protected]> + +- Update to 1.25.2: + * CVE-2026-14586: Assertion in libngtcp2 when under pressure in + high concurrency DNS-over-QUIC environments + [bsc#1271879] + * CVE-2026-32665: Remote DNS-over-QUIC denial of service due to + quic-size budget bypass + [bsc#1271873] + * CVE-2026-40691: Packet of death for DNSCrypt over TCP + [bsc#1271875] + * CVE-2026-41637: Degradation of resolution service from + improperly accounted client-terminated DNS-over-QUIC queries + [bsc#1271891] + * CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the + TTL of A/AAAA records disallowing a one-time 'ghost domain' + delegation renewal via glue records + [bsc#1271892] + * CVE-2026-44621: Libunbound applications configured with + 'unwanted-reply-threshold' could eventually be abruptly + terminated + [bsc#1271876] + * CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' + logic can shadow a stub/forward zone by a legitimate parent's + NXDOMAIN + [bsc#1271893] + * CVE-2026-44690: Cross-zone wildcard cache poisoning via + RRSIG.labels manipulation + [bsc#1271877] + * CVE-2026-46582: A wildcard replay, as another piece of data, + triggers poisoning in the serve expired reply path + [bsc#1271894] + * CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation + restarts + [bsc#1271878] + * CVE-2026-50046: Possible heap use-after-free in an error path + when a DoT forwarded query is jostled out + [bsc#1271882] + * CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers + instead of returning SERVFAIL + [bsc#1271880] + * CVE-2026-50248: BOGUS configured primary hostname accepted for + XFR in auth/rpz zones + [bsc#1271881] + * CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers + defensive full-cache flush + [bsc#1271883] + * CVE-2026-50252: Possible cache poisoning attack by mapping + source port population per thread + [bsc#1271884] + * CVE-2026-52863: Memory corruption could lead to crash and + denial of service + [bsc#1271885] + * CVE-2026-54478: DNS Cookie bypass when combined with + proxy-protocol use + [bsc#1271895] + * CVE-2026-55708: Privacy/configuration issue when adding local + data in views through 'unbound-control' + [bsc#1271896] + * CVE-2026-55717: 'serve-expired-client-timeout' and + 'response-ip' CNAME redirect could lead to a crash + [bsc#1271886] + * CVE-2026-55973: 'dns-error-reporting: yes' leads to stack + buffer overflow + [bsc#1271874] + * CVE-2026-55990: Packet of death for a DNSCrypt misconfigured + Unbound + [bsc#1271887] + * CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control + assertion failure in libngtcp2 + [bsc#1271888] + * CVE-2026-56416: Possible heap buffer overflow when validator + canonicalizes RDATA that contains domain name + [bsc#1271889] + * CVE-2026-56444: Degradation of resolution service when + 'discard-timeout' and 'serve-expired-client-timeout' are + combined in unusual configuration + [bsc#1271890] + +------------------------------------------------------------------- unbound.changes: same change Old: ---- unbound-1.25.1.tar.gz unbound-1.25.1.tar.gz.asc New: ---- unbound-1.25.2.tar.gz unbound-1.25.2.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libunbound-devel-mini.spec ++++++ --- /var/tmp/diff_new_pack.WmdW4P/_old 2026-07-26 11:29:54.785671317 +0200 +++ /var/tmp/diff_new_pack.WmdW4P/_new 2026-07-26 11:29:54.789671456 +0200 @@ -22,7 +22,7 @@ %bcond_without hardened_build # Name: libunbound-devel-mini -Version: 1.25.1 +Version: 1.25.2 #!BcntSyncTag: unbound Release: 0 Summary: Just a devel package for build loops ++++++ unbound.spec ++++++ --- /var/tmp/diff_new_pack.WmdW4P/_old 2026-07-26 11:29:54.841673251 +0200 +++ /var/tmp/diff_new_pack.WmdW4P/_new 2026-07-26 11:29:54.841673251 +0200 @@ -43,7 +43,7 @@ %define piddir /run Name: unbound -Version: 1.25.1 +Version: 1.25.2 Release: 0 BuildRequires: flex BuildRequires: ldns-devel >= %{ldns_version} ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.WmdW4P/_old 2026-07-26 11:29:54.901675323 +0200 +++ /var/tmp/diff_new_pack.WmdW4P/_new 2026-07-26 11:29:54.905675461 +0200 @@ -1,6 +1,6 @@ -mtime: 1779969446 -commit: 50be2f35409223f8718655a3041fd431a6b5203f87f600530f5f7b8fc35c68a7 +mtime: 1784804306 +commit: 1ae99043bef9609c6bf28a83e24083a19f01757e41398269dd35446bb65d258f url: https://src.opensuse.org/dns/unbound -revision: 50be2f35409223f8718655a3041fd431a6b5203f87f600530f5f7b8fc35c68a7 +revision: 1ae99043bef9609c6bf28a83e24083a19f01757e41398269dd35446bb65d258f projectscmsync: https://src.opensuse.org/dns/_ObsPrj.git ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-07-23 12:58:26.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ unbound-1.25.1.tar.gz -> unbound-1.25.2.tar.gz ++++++ /work/SRC/openSUSE:Factory/unbound/unbound-1.25.1.tar.gz /work/SRC/openSUSE:Factory/.unbound.new.2004/unbound-1.25.2.tar.gz differ: char 25, line 1
