Hi,

On Tue, Jul 21, 2026 at 03:24:15PM +0200, Ondřej Surý wrote:
> Package: unbound
> Version: 1.22.0-2+deb13u3
> Severity: critical
> Justification: causes serious data loss
> X-Debbugs-Cc: [email protected]
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
> 
> Dear Maintainer,
> 
> I've been told by several root nameservers that version of unbound
> as shipped by Debian has a serious flaw that causes unbound to double
> the traffic to the root zone system endangering the whole stability
> of the DNS system (the RZ operators could still cope with this, but
> doubling the traffic is quite horrible).
> 
> There has been large operator that upgraded to Debian Trixie and
> enabled serve-stale and this has caused several eyebrows to raise,
> and people coming to me (since they know I am DD) asking if I can
> help.
> 
> NLNetLabs had been notified, but since this is already fixed in
> the upstream packages, this needs to be expeditely fixed in Debian
> as this can cause instability in the DNS ecosystem.
> 
> Please look into this as soon as possible, or ping me if you want
> me to NMU unbound via security-team.  I am notifying the security
> team as well.

IMHO the security archive is not for such bugfixes (and as this is not
a security issue in unbound), so an update via a stable-update (with a
SUA advisory) seems more appropriate.

See: https://wiki.debian.org/StableUpdates
https://lists.debian.org/debian-stable-announce/

Regards,
Salvatore

Reply via email to