diff options
| author | Dag-Erling Smørgrav <des@FreeBSD.org> | 2026-05-29 22:21:50 +0000 |
|---|---|---|
| committer | Mark Johnston <markj@FreeBSD.org> | 2026-06-07 17:48:17 +0000 |
| commit | a68c183e0ad2ceefa2a1ea8f8c8d1d1937c36c0d (patch) | |
| tree | 418ab8c3a52498ad53aad02d1ce3f7fb900e176b /sys/dev/netmap/netmap_kloop.c | |
| parent | 744f62ccbf823fc8d9dfdb2ffb91723c9e9fe7da (diff) | |
unbound: Apply upstream patches
- Use the same EDE removal logic when encoding errors as when encoding
replies.
- Fix CVE-2026-33278, Possible remote code execution during DNSSEC
validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-42944, Heap overflow and crash with multiple nsid,
cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
- Fix CVE-2026-42959, Crash during DNSSEC validation of malicious
content. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew
Griffiths from 'calif.io' for the report.
- Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to Qifan
Zhang, Palo Alto Networks, for the report.
- Fix CVE-2026-41292, Parsing a long list of incoming EDNS options
degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan
Zhang from Palo Alto Networks, for the report.
- Fix CVE-2026-42534, Jostle logic bypass degrades resolution
performance. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash
calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
- Fix CVE-2026-42960, Possible cache poisoning attack while following
delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and
JianJun Chen, Tsinghua University, for the report.
- Fix CVE-2026-44390, Unbounded name compression in certain cases causes
degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
- Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to
Qifan Zhang, Palo Alto Networks, for the report.
Approved by: so
Security: FreeBSD-SA-26:33.unbound
Security: CVE-2026-33278
Security: CVE-2026-42944
Security: CVE-2026-42959
Security: CVE-2026-32792
Security: CVE-2026-40622
Security: CVE-2026-41292
Security: CVE-2026-42534
Security: CVE-2026-42923
Security: CVE-2026-42960
Security: CVE-2026-44390
Security: CVE-2026-44608
Diffstat (limited to 'sys/dev/netmap/netmap_kloop.c')
0 files changed, 0 insertions, 0 deletions
