head 1.1; branch 1.1.1; access ; symbols unbound-1-26-1:1.1.1.1 NLNETLABS:1.1.1; locks ; strict; comment @# @; 1.1 date 2026.09.17.14.22.53; author christos; state Exp; branches 1.1.1.1; next ; commitid fayiV3BcuZyYSYVG; 1.1.1.1 date 2026.09.17.14.22.53; author christos; state Exp; branches ; next ; commitid fayiV3BcuZyYSYVG; desc @@ 1.1 log @Initial revision @ text @; config options ; The island of trust is at test. server: target-fetch-policy: "0 0 0 0 0" qname-minimisation: "no" fake-sha1: yes trust-anchor-signaling: no minimal-responses: no iter-scrub-promiscuous: no aggressive-nsec: no local-zone: test. nodefault log-servfail: yes discard-timeout: 0 module-config: "respip iterator" serve-expired: yes serve-expired-client-timeout: 500 serve-expired-ttl: 3600 serve-expired-reply-ttl: 30 rpz: name: "rpz.example.com." rpz-log: yes rpz-log-name: "rpz.example.com" zonefile: TEMPFILE_NAME rpz.example.com TEMPFILE_CONTENTS rpz.example.com $ORIGIN example.com. rpz 3600 IN SOA ns1.rpz.example.com. hostmaster.rpz.example.com. ( 1379078166 28800 7200 604800 7200 ) 3600 IN NS ns1.rpz.example.com. 3600 IN NS ns2.rpz.example.com. $ORIGIN rpz.example.com. 24.0.2.0.192.rpz-ip CNAME . TEMPFILE_END stub-zone: name: "." stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET. CONFIG_END SCENARIO_BEGIN Test expired response RPZ rewrite ; K.ROOT-SERVERS.NET. RANGE_BEGIN 0 100 ADDRESS 193.0.14.129 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION . IN NS SECTION ANSWER . IN NS K.ROOT-SERVERS.NET. SECTION ADDITIONAL K.ROOT-SERVERS.NET. IN A 193.0.14.129 ENTRY_END ENTRY_BEGIN MATCH opcode subdomain ADJUST copy_id copy_query REPLY QR NOERROR SECTION QUESTION test. IN NS SECTION AUTHORITY test. IN NS ns.test. SECTION ADDITIONAL ns.test. IN A 1.2.3.5 ENTRY_END RANGE_END ; ns.test RANGE_BEGIN 0 100 ADDRESS 1.2.3.5 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION test. IN NS SECTION ANSWER test. IN NS ns.test SECTION ADDITIONAL ns.test. IN A 1.2.3.5 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.test. IN A SECTION ANSWER ns.test. IN A 1.2.3.5 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.test. IN AAAA SECTION AUTHORITY test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600 ENTRY_END ENTRY_BEGIN MATCH opcode subdomain ADJUST copy_id copy_query REPLY QR NOERROR SECTION QUESTION example.test. IN NS SECTION AUTHORITY example.test. IN NS ns.example.test. SECTION ADDITIONAL ns.example.test. IN A 1.2.3.4 ENTRY_END ENTRY_BEGIN MATCH opcode subdomain ADJUST copy_id copy_query REPLY QR NOERROR SECTION QUESTION far.test. IN NS SECTION AUTHORITY far.test. IN NS ns.far.test. SECTION ADDITIONAL ns.far.test. IN A 1.2.3.6 ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 0 20 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION example.test. IN NS SECTION ANSWER example.test. IN NS ns.example.test. SECTION ADDITIONAL ns.example.test. IN A 1.2.3.4 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN A SECTION ANSWER ns.example.test. IN A 1.2.3.4 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN AAAA SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 ENTRY_END ; response to query of interest ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION www.example.test. IN A SECTION ANSWER www.example.test. 1 IN A 192.0.2.1 ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 20 100 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN A SECTION ANSWER ns.example.test. IN A 1.2.3.4 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN AAAA SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR SERVFAIL SECTION QUESTION www.example.test. IN A SECTION ANSWER ENTRY_END RANGE_END ; ns.far.test. RANGE_BEGIN 0 100 ADDRESS 1.2.3.6 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION far.test. IN NS SECTION ANSWER far.test. IN NS ns.far.test. SECTION ADDITIONAL ns.far.test. IN A 1.2.3.6 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.far.test. IN A SECTION ANSWER ns.far.test. IN A 1.2.3.6 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.far.test. IN AAAA SECTION AUTHORITY far.test. 3600 IN SOA ns.far.test. host.far.test. 20301 3600 1800 604800 3600 ENTRY_END ; response to query of interest ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION tgt.far.test. IN A SECTION ANSWER tgt.far.test. 1 IN A 10.20.30.40 ENTRY_END RANGE_END ; Put items with TTL 1 in cache. STEP 1 QUERY ENTRY_BEGIN REPLY RD DO SECTION QUESTION tgt.far.test. IN A ENTRY_END STEP 2 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO NOERROR SECTION QUESTION tgt.far.test. IN A SECTION ANSWER tgt.far.test. 1 IN A 10.20.30.40 ENTRY_END STEP 10 QUERY ENTRY_BEGIN REPLY RD DO SECTION QUESTION www.example.test. IN A ENTRY_END STEP 11 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO NXDOMAIN SECTION QUESTION www.example.test. IN A SECTION ANSWER ENTRY_END ; Move time to expire the cache entries. STEP 20 TIME_PASSES ELAPSE 2 ; the upstream RANGE is removed, so serve-expired has to act. STEP 30 QUERY ENTRY_BEGIN REPLY RD DO SECTION QUESTION www.example.test. IN A ENTRY_END ; for serve expired callback. STEP 31 TIME_PASSES ELAPSE 2 STEP 40 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO NXDOMAIN SECTION QUESTION www.example.test. IN A SECTION ANSWER ENTRY_END ; The pending lookup for the data, that was answered with expired to the client. STEP 50 TRAFFIC SCENARIO_END @ 1.1.1.1 log @Import unbound-1.26.1 (previous was unbound-1.25.1) Unbound 1.26.1 ============== This release has a number of security fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-77860, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-81634, CVE-2026-81642, CVE-2026-82717, CVE-2026-82720 and CVE-2026-85501. Bug Fixes Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber, for the report. Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report. Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, for the report. In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue. Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report. Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, for the report. Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for the report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report. Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report. Unbound 1.26.0 ============== This release has some features and a number of bug fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . The certificates for the root key are updated. The icannbundle.pem file is updated with the public keys for 2009 to 2029 and for 2025 to 2045. This is available in the unbound-anchor tool. With the -l option unbound-anchor lists the builtin key and cert that it has. The updated certificates are valid for a longer time. With -c the icannbundle.pem file can be given from the commandline. Then unbound-anchor does not use the builtin certificates. And this allows the update of the certificate file without a change in unbound-anchor. The ipsecmod module is changed, that the script, for the hook, has to start with a line like #!/bin/sh. The file is executed with execv, and not any longer with system, so that it is better for security. It is an in-depth protection against possible quotation and buffer failures. The server continues to start if secondary zones, for auth zones, fail to load from zonefile. To protects against malformed content in the zonefiles, and the server continues to serve, and attempt to fetch new updates for the zone. Also for primary auth zones, if the zonefile does not exist, the server continues to start up. This makes the server start more easily. Secondary zones are no longer allowed to have a $INCLUDE in the zonefile. That is for safety, for what file is chosen. The server drops out-of-zone content from auth zones when they are read, those records are not supposed to be part of the auth zone. The primary hostname that is transferred from, can now be a name that uses CNAME(s). The options max-transfer-size and max-transfer-time can be used to limit the amount of size and time that auth-zone transfers use. The default is disabled, that is backwards compatible. The unbound-control command local_data_remove is overloaded to also work to be able to remove specific records. Specify the record with its details to remove it. Apart from the local-zone type block_a, that denies A lookups, there is now also block_aaaa, it denies AAAA lookups. The local zone types block_a_wdata and block_aaaa_wdata can be used to also have local-data, that is served, if it is not there, like transparent, it lookups recursively, or denies the particular type from lookup. These are helpful in IPv4 with IPv6 deployment situations, as it forces applications to not use a particular transport. With the changes to respip and RPZ processing that make the filters apply equally after dns64, so that dns64 does not bypass the filter, the new local-zone types can be used to apply denial of a particular transport. Features Update icannbundle.pem certificates in unbound-anchor. It has the public keys for 2009 to 2029 and for 2025 to 2045. Fix to add max-transfer-size and max-transfer-time that limit auth-zone and rpz transfer amount and time taken. Default is disabled. This hardens against unbounded transfers. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Merge #1087: Overload local_data_remove to support removing specific records. Merge #1433 from jisakiel: Add new static zone type block_aaaa to suppress AAAA queries. Fix #1477: respip + dns64: dns64 uses A records modified by respip instead of original A records. Adds local-zone types block_a_wdata and block_aaaa_wdata, that are like block_a and block_aaaa, and uses local-data if present. Bug Fixes Fix windows 64bit build for libssp dependency. iana portlist updated. Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation in setup_if() - outside_network_create(). This fixes that large values for num_ports do not overflow and create invalid references after integer truncation. Thanks to Karnakar Reddy (@@karnakarreddi) for the report. Fix to clean up log ids after a failure to start a worker thread. Fix to relax assertions after the TTL 0 handling change. This relaxes an assertion in cachedb (it fails instead), and for packet_rrset_copy_region. Fix comment and verbose logging for EDNS fallback buffer size. Fix man page entry for so-sndbuf, it is for responses sent out. Fix val_find_DS for robustness, to check the result of packet_rrset_copy_region before using it. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix that for dns64 answers, the AAAA query is checked to be DNSSEC validated, when DNSSEC is enabled. This improves the RFC6147 conformance of Unbound. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. In addition, thanks to Qifan Zhang, Palo Alto Networks, for reporting it. Fix for allocation-failure hardening of rrset cache wildcard storage and canonical NSEC owner replacement. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix DNSSEC validation with libnettle for noncanonical RSA DNSKEYs with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix DNSKEY size calculation for noncanonical RSA DNSKEYs with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix for mixed class referrals, the resolver uses the query class. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Unit test for CVE-2026-33278. Unit test for CVE-2026-42944. Unit test for CVE-2026-42959. Unit test for CVE-2026-40622. Unit test for CVE-2026-42960. Fix in depth for serve-expired responses from cachedb, that it does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix lame server detection, for selfpointed glue records. Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua University for the report. Fix cleaning up DoH session. The same query can be on multiple streams in a session. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix for signed same-owner CNAME and ordinary RRset responses. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix for mesh new client and mesh new callback to rollback the added address, tcp mesh state and callback when there is a failure to initialize. This fixes the mesh accounting of reply addresses. Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for the report Fix for autotrust state-file line overflow, that can give hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to limit the DSNS per-label walk in the iterator. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that the ratelimit is decremented on successful referrals. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that msgencode insert_query has the correct assertion, for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to reset the tcp-timeout before applying a load based reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to decrement the per-netblock tcp connection limits, so it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix manual to document ratelimit, that it is for target nameservers for a domain, and keeps queries limited. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix, in depth, for respip rewrite of dns64 responses. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that dns64 with subnetcache does not write ECS scoped answers to global cache. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix ipset module for name too long checks, race conditions on local name buffer, and for socket close race condition. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that validator caps number of ANY RRsets it can validate, and the wait timer is shortened. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix analyzer warning in mesh_new_client. Fix #1457: race condition causes segfault when starting threads. Fix header_seen detection for trust anchor files, so that it detects the id line. Fix unit test to check for new icannbundle.pem. Fix const as reported by newest compiler warnings. Fix that the processing of class responses does not have a heap use-after-free. That could happen if at least two distinct classes are configured for resolution. Thanks to Qifan Zhang, Palo Alto Networks for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this. Fix negative cache to work with NSEC3 records without salt. Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix parse of svcbparam ech, it had incorrect length. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix that quotation and escaping works the same in auth-zone url content, as in the zonefile read. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix ipset module to use larger domain name buffers, and check buffer lengths. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix PROXYv2 header read and consume, it checks the header size. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix negative cach... Unbound 1.25.2 ============== This release has a number of security fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-14586, CVE-2026-32665, CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621, CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045, CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251, CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708, CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991, CVE-2026-56416 and CVE-2026-56444. Bug Fixes Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments. Thanks to Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for the report. Fix CVE-2026-32665, Remote DNS-over-QUIC denial of service due to quic-size budget bypass. Thanks to N0zoM1z0 (https://github.com/N0zoM1z0) for the report. In addition, thanks to Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for also reporting this issue. In addition, thanks to Qifan Zhang, Palo Alto Networks, for also reporting this issue. In addition, thanks to Xuanchao Xie, for also reporting this issue. Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Trung Nguyen (@@everping) of CyStack, for also reporting this issue. Fix CVE-2026-41637, Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44621, Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-46582, A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation restarts. Thanks to Kunjie Shang, University of Science and Technology of China, for the report. Fix CVE-2026-50046, Possible heap use-after-free in an error path when a DoT forwarded query is jostled out. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50248, BOGUS configured primary hostname accepted for XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50252, Possible cache poisoning attack by mapping source port population per thread. Thanks to Inbal Schussheim and Amit Klein, Hebrew University, for the report. Fix CVE-2026-52863, Memory corruption could lead to crash and denial of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-54478, DNS Cookie bypass when combined with proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55708, Privacy/configuration issue when adding local data in views through 'unbound-control'. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this issue. Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xuanchao Xie, for also reporting this issue. Fix CVE-2026-56416, Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-56444, Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this issue. In addition, thanks to Haruki Oyama (Waseda University), for also reporting this issue. @ text @@