pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/net/unbound



Module Name:    pkgsrc
Committed By:   kim
Date:           Mon Sep 21 09:44:22 UTC 2026

Modified Files:
        pkgsrc/net/unbound: Makefile distinfo
        pkgsrc/net/unbound/patches: patch-configure

Log Message:
unbound: update to 1.26.1

This release consolidates security fixes for issues reported over
a period of time. There are fixes for CVE-2026-77860, CVE-2026-77955,
CVE-2026-78227, CVE-2026-80225, CVE-2026-81634, CVE-2026-81642,
CVE-2026-82717, CVE-2026-82720 and CVE-2026-85501.

Bug Fixes

- Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code
  Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li
  from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC
  canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber,
  for the report.
- Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption.
  Thanks to Ben Morris from Anthropic for the report.
- Fix CVE-2026-77955, Possible ZONEMD verification bypass window.
  Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
  for the report. In addition, thanks to Qifan Zhang from Palo Alto
  Networks for also reporting this issue.
- Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on
  reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai
  University, AOSP Lab for the report.
- Fix CVE-2026-80225, Possible degradation of service from continuous
  queries on the same TCP/DoT connection. Thanks to Qifan Zhang from
  Palo Alto Networks for the report.
- Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path.
  Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab,
  for the report.
- Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch
  Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and
  Xiang Li from Nankai University, AOSP Lab for the report. In
  addition, thanks to Qifan Zhang from Palo Alto Networks for a
  complimentary report.
- Fix CVE-2026-77860, ‘serve-expired’ can bypass Unbound ‘wait-limit’.
  Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the
  University of Science and Technology of China (USTC) for the
  report.


To generate a diff of this commit:
cvs rdiff -u -r1.138 -r1.139 pkgsrc/net/unbound/Makefile
cvs rdiff -u -r1.92 -r1.93 pkgsrc/net/unbound/distinfo
cvs rdiff -u -r1.9 -r1.10 pkgsrc/net/unbound/patches/patch-configure

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/net/unbound/Makefile
diff -u pkgsrc/net/unbound/Makefile:1.138 pkgsrc/net/unbound/Makefile:1.139
--- pkgsrc/net/unbound/Makefile:1.138   Wed Aug 26 10:19:09 2026
+++ pkgsrc/net/unbound/Makefile Mon Sep 21 09:44:22 2026
@@ -1,7 +1,6 @@
-# $NetBSD: Makefile,v 1.138 2026/08/26 10:19:09 adam Exp $
+# $NetBSD: Makefile,v 1.139 2026/09/21 09:44:22 kim Exp $
 
-DISTNAME=      unbound-1.26.0
-PKGREVISION=   1
+DISTNAME=      unbound-1.26.1
 CATEGORIES=    net
 MASTER_SITES=  https://nlnetlabs.nl/downloads/unbound/
 

Index: pkgsrc/net/unbound/distinfo
diff -u pkgsrc/net/unbound/distinfo:1.92 pkgsrc/net/unbound/distinfo:1.93
--- pkgsrc/net/unbound/distinfo:1.92    Thu Aug 13 09:26:02 2026
+++ pkgsrc/net/unbound/distinfo Mon Sep 21 09:44:22 2026
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.92 2026/08/13 09:26:02 adam Exp $
+$NetBSD: distinfo,v 1.93 2026/09/21 09:44:22 kim Exp $
 
-BLAKE2s (unbound-1.26.0.tar.gz) = 724d14c740fd50c4f5c9143e3d5ad22b0b2e431b3a7fbf28160f41a21c293b1a
-SHA512 (unbound-1.26.0.tar.gz) = d061a4fd89b83e9e2c122b4479547f86548856710c801df01ce0aff8f0b4df9a61760cb7418b8ba7c79d504e6af49d7affc480f0730890bc818709007a931efd
-Size (unbound-1.26.0.tar.gz) = 6945614 bytes
-SHA1 (patch-configure) = dc26a7799d5001fe86c3742160633152309a670f
+BLAKE2s (unbound-1.26.1.tar.gz) = 876b749d8f3b74a0fd39e852f9579c3b7bd1f5532f68682c9dceffbb15c8351d
+SHA512 (unbound-1.26.1.tar.gz) = b0a02fe77e5d0ad697e950ee0c13b987f0f33b489dfe4bf4ed0b09723ca883ebe4465f69625b7d4eba8171516e6879bb07bf8c22b6e8bdd357e2f4f43e485525
+Size (unbound-1.26.1.tar.gz) = 6948585 bytes
+SHA1 (patch-configure) = 37abfa057f57c7ca712972ce06de8f09d667c2c6

Index: pkgsrc/net/unbound/patches/patch-configure
diff -u pkgsrc/net/unbound/patches/patch-configure:1.9 pkgsrc/net/unbound/patches/patch-configure:1.10
--- pkgsrc/net/unbound/patches/patch-configure:1.9      Thu Aug 13 09:26:02 2026
+++ pkgsrc/net/unbound/patches/patch-configure  Mon Sep 21 09:44:22 2026
@@ -1,4 +1,4 @@
-$NetBSD: patch-configure,v 1.9 2026/08/13 09:26:02 adam Exp $
+$NetBSD: patch-configure,v 1.10 2026/09/21 09:44:22 kim Exp $
 
 Properly detect pthread_set_name_np() by linking, not compiling, as
 -Wno-implicit-function-declaration can result with false positive.
@@ -6,9 +6,9 @@ Properly detect pthread_set_name_np() by
 Pretend expat.h is found: it is guaranteed by PkgSrc, but on Darwin it might
 be buried inside an SDK; we don't want the SDK path being exposed in CFLAGS.
 
---- configure.orig     2026-08-04 07:08:52.000000000 +0000
+--- configure.orig     2026-09-16 07:35:56.000000000 +0000
 +++ configure
-@@ -20407,7 +20407,7 @@ main (void)
+@@ -19905,7 +19905,7 @@ main (void)
    return 0;
  }
  _ACEOF
@@ -17,7 +17,7 @@ be buried inside an SDK; we don't want t
  then :
  
            { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
-@@ -20521,7 +20521,7 @@ main (void)
+@@ -20016,7 +20016,7 @@ main (void)
    return 0;
  }
  _ACEOF
@@ -26,7 +26,7 @@ be buried inside an SDK; we don't want t
  then :
  
            { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: yes" >&5
-@@ -23841,7 +23841,7 @@ fi
+@@ -23215,7 +23215,7 @@ fi
  
  { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for libexpat" >&5
  printf %s "checking for libexpat... " >&6; }



Home | Main Index | Thread Index | Old Index