head 1.1; branch 1.1.1; access ; symbols unbound-1-26-1:1.1.1.1 NLNETLABS:1.1.1; locks ; strict; comment @# @; 1.1 date 2026.09.17.14.22.51; author christos; state Exp; branches 1.1.1.1; next ; commitid fayiV3BcuZyYSYVG; 1.1.1.1 date 2026.09.17.14.22.51; author christos; state Exp; branches ; next ; commitid fayiV3BcuZyYSYVG; desc @@ 1.1 log @Initial revision @ text @; config options ; The island of trust is at test. server: access-control: 10.0.0.0/8 allow trust-anchor: "test. DS 1444 8 2 8a87d067fd09a5965244fe2e317dd26d182c468e0a7f26ecc4c7b479bf89db9b" val-override-date: "20201020135527" target-fetch-policy: "0 0 0 0 0" qname-minimisation: "no" fake-sha1: yes trust-anchor-signaling: no minimal-responses: no iter-scrub-promiscuous: no aggressive-nsec: yes local-zone: test. nodefault log-servfail: yes ; otherwise after timers, the old replies are discarded as old. discard-timeout: 0 stub-zone: name: "." stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET. CONFIG_END SCENARIO_BEGIN Test sub DS deep copy during DNSSEC validation suspension ; K.ROOT-SERVERS.NET. RANGE_BEGIN 0 20 ADDRESS 193.0.14.129 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION . IN NS SECTION ANSWER . IN NS K.ROOT-SERVERS.NET. SECTION ADDITIONAL K.ROOT-SERVERS.NET. IN A 193.0.14.129 ENTRY_END ENTRY_BEGIN MATCH opcode subdomain ADJUST copy_id copy_query REPLY QR NOERROR SECTION QUESTION test. IN NS SECTION AUTHORITY test. IN NS ns.test. SECTION ADDITIONAL ns.test. IN A 1.2.3.5 ENTRY_END RANGE_END ; ns.test RANGE_BEGIN 0 20 ADDRESS 1.2.3.5 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION test. IN NS SECTION ANSWER test. IN NS ns.test test. 3600 IN RRSIG NS 8 1 3600 20201116135527 20201019135527 1444 test. RGCxIO32TbbLTk6xZmTr+fjYPH50hntBxeOQ2DIj2pDsmjALcHYtVkOfpfk2EhOhHZd+9PLuoJPbJh6a9NqLSFeBvr0XZoCZoQ2g0tCHUNHcH5EVjA2TuYBQem6DVYnPLJ3914aRx0uA1j42b8dC2xsam/XkOo7U+dLbUW2Os1s= SECTION ADDITIONAL ns.test. IN A 1.2.3.5 ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.test. IN A SECTION ANSWER ns.test. IN A 1.2.3.5 ns.test. 3600 IN RRSIG A 8 2 3600 20201116135527 20201019135527 1444 test. GskCc4/k6GjH9V9Jz2V5L2XLiizbOeWkB0feSbf+aN859S3vxVvtuqkvIgwY4LafUO1QAn/pUcv9zA7rcFO++rlg+8t6gvZTo9p3v0bfeIv2uJDsfSBD5jDh0WXlxjekfnrKrQp7zE+GiA93tWwKUWKPvxXDgP+n886e6WcbHJw= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.test. IN AAAA SECTION AUTHORITY test. 3600 IN SOA ns.test. host.test. 20201 3600 1800 604800 3600 test. 3600 IN RRSIG SOA 8 1 3600 20201116135527 20201019135527 1444 test. IZJIDmEgf0W7A5G7hvvZ2hUqJ9Trbv1/i7ySapDmPbYV9lVCmHHobySxO01yDhI2/Pvpsvxqrm1Tiv3BxH8uzZ4keKgiQjBsSy4htAsFct9I4E7ly2glPj/Fm3oun3PsjJDv5QYhx0KS7w4IQKU7Nc9pfJc92uoUI5bdoC1pRGw= ns.test. 3600 IN NSEC nz.test. A RRSIG ns.test. 3600 IN RRSIG NSEC 8 2 3600 20201116135527 20201019135527 1444 test. PElArVB3KPg8KHAP7lzcNbhFuXNxTsHNTn1dZVncB5qmWRdIaeKpaXDjpH0JSXMaelGFS+/QhuQ6Hmw9+4VyZFRqMzGhw4agUR/2bxABHcDIG4ZpUwyeSP61ATTfHUkQVxaH2wjCWI/tfmesdP2xVE4GXyUvCIBxU914MkZbULU= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION test. IN DNSKEY SECTION ANSWER test. 3600 IN DNSKEY 257 3 8 AwEAAbd9WqjzE2Pynz21OG5doSf9hFzMr5dhzz2waZ3vTa+0o5r7AjTAqmA1yH/B3+aAMihUm5ucZSfVqo7+kOaRE8yFj9aivOmA1n1+JLevJq/oyvQyjxQN2Qb89LyaNUT5oKZIiL+uyyhNW3KDR3SSbQ/GBwQNDHVcZi+JDR3RC0r7 ;{id = 1444 (ksk), size = 1024b} test. 3600 IN RRSIG DNSKEY 8 1 3600 20201116135527 20201019135527 1444 test. UmRMS4iG9NBBHZYOtpwFFcJgbEb5SfHSgHd9XRe/8pTWM31WSDayn5ViPOBMqI1T5TXg2amc13dDI574xIM2oKMus3b5cBW72jJLW13jprBtslO6P8BMWb4HNnvLrJtQjwf3ErRirtTxinLmywQtmyr1cdthyG3Gp4N7i90fHSc= SECTION ADDITIONAL ENTRY_END ENTRY_BEGIN MATCH opcode qname qtype ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION example.test. IN DS SECTION ANSWER example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39 example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I= ENTRY_END ENTRY_BEGIN MATCH opcode subdomain ADJUST copy_id copy_query REPLY QR NOERROR SECTION QUESTION example.test. IN NS SECTION AUTHORITY example.test. IN NS ns.example.test. example.test. 3600 IN DS 55567 8 2 a2d578906330a10a57d40462257b6ce038bad3f7bf4a45c46c46086e20a94b39 example.test. 3600 IN RRSIG DS 8 2 3600 20201116135527 20201019135527 1444 test. P7+FTYW2qHuJ4I1YbuvseEz5X1lOYAraGEHB3C5y0OOCQFmhmSiFRdquNi2NlpcS6FXLdsE0EU+Bo1+0atTG4EkMWXbpF21lrtbB51BdsnlX4Mzc/o375fvjiOMwmF6wPCUaOUN62jrVrhsE/hedaVyDphDToqL17ETohwgUO2I= SECTION ADDITIONAL ns.example.test. IN A 1.2.3.4 ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 0 25 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION example.test. IN NS SECTION ANSWER example.test. IN NS ns.example.test. example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4= SECTION ADDITIONAL ns.example.test. IN A 1.2.3.4 ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN A SECTION ANSWER ns.example.test. IN A 1.2.3.4 ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN AAAA SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG ns.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. v/5aO/n8Ow21y7LE7JKZsFkUJU5MjIfadVRm2Tdb8f3RLwYDdBTs3aWeeEQdCRSUF61TmfJM1jIxlWQPuHbqzGnjSk7adw9gFpP7wFwoqG3/xdCFHoxo/3/1F/4Ankey3sDgKgOFsgnu40TlL36mGPYszeK+/2o3SAx2GM+3BdU= ENTRY_END ; response to DNSKEY priming query ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION example.test. IN DNSKEY SECTION ANSWER example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b} example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g= ENTRY_END ; response to query of interest ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION www.example.test. IN A SECTION ANSWER www.example.test. IN A 1.2.3.4 www.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. sbK517uW0iiO1FbJ+rCSrISg6RoIsXAFmd8NgF9mERAefkiVYTjUxdm4USccVg4Xwig9S14yANFPXY1QQbTxx25mcOdw4wyJUjGZosaIYS2DSTsAnDSgEOHPiEnYM84/UCjfWY54P4SFnCx8esaZfSdMu6YG+d3CxR1wJGloju4= ENTRY_END RANGE_END ; ns.example.test. later at 50 RANGE_BEGIN 50 55 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION example.test. IN NS SECTION ANSWER example.test. IN NS ns.example.test. example.test. 3600 IN RRSIG NS 8 2 3600 20201116135527 20201019135527 55567 example.test. l1JT0wMlK0YI7/CWHzexf/k0iafUhCgN+BdgjBXIRXmSQNf4HDTiAkbcWL2/15qtnp12nQy9JeiTdSQ3vtPoHAJX4C5uTWaze4ms+Wrrf+n92sLCjacP9x50uuicH3URT6cKb1QCAPwlvlWxIlZjAMYFScSns7+C441NMJT8aE4= SECTION ADDITIONAL ns.example.test. IN A 1.2.3.4 ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN A SECTION ANSWER ns.example.test. IN A 1.2.3.4 ns.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. 2PWaVaccZFQgfPKXNsdEGYUVaashCAj1ZhBo9XRt5eQKUFvZcauBjMnXIuxZFyWeootn1fZGw6GuPI5W48Y0FDx38H6adprkFgQikso2Y64jDdDMWznSo38Z/XqP+U0+kq4vmwonvmEMpm7hKnNEXvhqGKyGzyBwb+CZVJ2L8Eo= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ns.example.test. IN AAAA SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= ns.example.test. 3600 IN NSEC nz.example.test. A RRSIG ns.example.test. 3600 IN RRSIG NSEC 8 3 3600 20201116135527 20201019135527 55567 example.test. v/5aO/n8Ow21y7LE7JKZsFkUJU5MjIfadVRm2Tdb8f3RLwYDdBTs3aWeeEQdCRSUF61TmfJM1jIxlWQPuHbqzGnjSk7adw9gFpP7wFwoqG3/xdCFHoxo/3/1F/4Ankey3sDgKgOFsgnu40TlL36mGPYszeK+/2o3SAx2GM+3BdU= ENTRY_END ; response to DNSKEY priming query ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR NOERROR SECTION QUESTION example.test. IN DNSKEY SECTION ANSWER example.test. 3600 IN DNSKEY 257 3 8 AwEAAdug/L739i0mgN2nuK/bhxu3wFn5Ud9nK2+XUmZQlPUEZUC5YZvm1rfMmEWTGBn87fFxEu/kjFZHJ55JLzqsbbpVHLbmKCTT2gYR2FV2WDKROGKuYbVkJIXdKAjJ0ONuK507NinYvlWXIoxHn22KAWOd9wKgSTNHBlmGkX+ts3hh ;{id = 55567 (ksk), size = 1024b} example.test. 3600 IN RRSIG DNSKEY 8 2 3600 20201116135527 20201019135527 55567 example.test. IbWMC6quOuZFNPAVxQLqCJ9nLhindBo826rnLcg5yMgs9dGUSPOCXAfHTmbgJAUNs9HTFfrJWNvasnETs0UOpmEuifGwWdH1OlME7Gny4RL2QmITUFeMW81Jz1tiVQxFXl6yxT0jxOxvz+bqMHlrz+8IeWQXcO+GZTPu8ueq30g= ENTRY_END ; response to query of interest ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION aaa.parcel.example.test. IN A SECTION ANSWER aaa.parcel.example.test. IN A 1.2.3.5 ;aaa.parcel.example.test. 3600 IN RRSIG A 8 4 3600 20201116135527 20201019135527 55567 example.test. eFryWdR6+3OiuHnbOFnpEt2sVeMJw+maoPZPoiut24b0oGruN85ujzooVwYjvl+IPiEJo+sajnGhG9R5Uibvw1zg1LX0fATYytCVNSKGdjYEiO3+1yyiq1lxlo/zaxJi2Vl750s250ooIpQo/6zQVoIfHKDFSif4Xb4bFeRBTUY= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION bbb.parcel.example.test. IN A SECTION ANSWER bbb.parcel.example.test. IN A 1.2.3.6 ;bbb.parcel.example.test. 3600 IN RRSIG A 8 4 3600 20201116135527 20201019135527 55567 example.test. mm2EmvC5UE1MCFw7lHNUE9tlrvSDr6IKUrC143YohY+S22Fb1RkmxmQIKcNVasZ8O+YJKOsiIz2+2iWvjhFMHXC7Y7QLu19Qe9ndQ4cx4mYUTFkA5imQkqiV9CJLCi9cjoCayJUDxAuT7pq6Y1VPIn0AUWNmcPNUZcYgy8NSe1A= ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 60 70 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION parcel.example.test. IN DS SECTION ANSWER SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= 00000001.example.test. 3600 IN NSEC3 1 0 5 AA 00000002 A RRSIG 00000001.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. e8JQpXALnirEp55SDzotEv/nBj1K+Rnx8BgNQQ74grKFHcrTx1xcJo2uhD5JSJk+5A11oWRcnzYwGYZyzjw4h9UBz7XZQogcvL5igPGbvtK71DiPnIMMj7aN/7yl/Q2gdkCqr0bBi2ZWO6AzGG90K33IlW2ZrttdaDzTNsF43rk= 00000002.example.test. 3600 IN NSEC3 1 0 5 BB 00000003 A RRSIG 00000002.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. b0jlxmbQqwGxB7jkiMW3PeEnvv9kBYHQ24qCgDXqpeqMfQxpEoXrSxmipI3JitV2FZqvNw+mJJ7Wy5kEGLvOqHJhxcPlbOJjVH2UDhWVNh0fR6UFGwZb62xaQMlltlUszFUNvbdIN4sO4EaLn2C1/LePUlQHWKZs2DCUbG6JOM4= 00000003.example.test. 3600 IN NSEC3 1 0 5 CC 00000004 A RRSIG 00000003.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. E0K4skeGIEfxlxHkJRBoES23n95OYtRz8KIvbcCHTXYCuM+CKnKtTCdVtgDYcx2IdyvXNDTaoylNpOAJ4IGLYNbCTCeIScQdTSB8meqDV/nFvlARcgz6ptCwi6gRoe4xpQ7T1v/h6/MFKr5BDqwFk2tDtz21Bpf8NoMLLPWIjw8= 00000004.example.test. 3600 IN NSEC3 1 0 5 DD 00000005 A RRSIG 00000004.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. yX+fvu905NpBGT0YFUtG0K/qzV4znlqNwAfIvblEW6GEanU5tiolunXXi1QYSfn8AbsPzokADW2xfGDbdMDR2FEbv7SXwoO1iQX6Yh0Sgyr8EGsUz8fLCcpZS+hovZX421RePnZkqQBY9LESeDdDpfvuxQTrh4ILSYxTSdKyBgg= 00000005.example.test. 3600 IN NSEC3 1 0 5 EE 00000006 A RRSIG 00000005.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. REolHghL+AZ46rpw+e7RwfBzPC9O6RyXnfvM4JSBfxw2J0+b7uvRoK83CHEbvkPDDgPJR8N74H1OtvRL4EkifKR5Vr11VLUDcJmXYTNP2mmlA0rwsC625cGVdZzuJjK2bvva2Cnu5vdQvjFLBPn2LVb2rxlkXeEToAQNDJMhNHo= 00000006.example.test. 3600 IN NSEC3 1 0 5 11 00000007 A RRSIG 00000006.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. V/7Yv/HdEmfHr2hGUuzoEm9/ovRxQOgeiiOVWL4S2h0r+PDd2XlpnCvS4E+fJhNsY+xGhtrPRTJTjJjxfF2r8AxcXW0Wbf6ZdPZliAAFuIK/brX6T6ReMrNq8dmEiHqg92y66Ff+aDTIdL1ufMJ+JoaygsbPghFPkD61kjs6GMs= 00000007.example.test. 3600 IN NSEC3 1 0 5 22 00000008 A RRSIG 00000007.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. gh7itP+B2Aa+S/iXkCo5lLzHY5OvW2VzkmnZ9kmezlXlJA7LkUUcPj33nCk+lY7Bvno1SEcQAYi9tCHegMsqh/RZg5gmRKMN3sn2ob2P7vbXzNiFCPpXdzHAzsmLwR61MqMPtT7gNNajKecoTM0/VkRht3J1aJJxsrmuGXyu3oM= 00000008.example.test. 3600 IN NSEC3 1 0 5 33 00000009 A RRSIG 00000008.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. qVQ4/COf1vEtswdtl8NvcZWX9otn4cjYWvVrx8Y9XbvPnboIOTrKpuej16wo6k6ak6IBBOQkIK4KDIP3iHNBlZQsxTUoaxb7EyNQ/Fkou3HNkJuf3VAUM2d/UhCmKpx5EPbmY5WQ7erDuRGMSIHYivjPOsSuLhfpcc8/jtHDcRI= ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 160 170 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION parcel.example.test. IN DS SECTION ANSWER SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= 00000001.example.test. 3600 IN NSEC3 1 0 5 AA 00000002 A RRSIG 00000001.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. e8JQpXALnirEp55SDzotEv/nBj1K+Rnx8BgNQQ74grKFHcrTx1xcJo2uhD5JSJk+5A11oWRcnzYwGYZyzjw4h9UBz7XZQogcvL5igPGbvtK71DiPnIMMj7aN/7yl/Q2gdkCqr0bBi2ZWO6AzGG90K33IlW2ZrttdaDzTNsF43rk= 00000002.example.test. 3600 IN NSEC3 1 0 5 BB 00000003 A RRSIG 00000002.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. b0jlxmbQqwGxB7jkiMW3PeEnvv9kBYHQ24qCgDXqpeqMfQxpEoXrSxmipI3JitV2FZqvNw+mJJ7Wy5kEGLvOqHJhxcPlbOJjVH2UDhWVNh0fR6UFGwZb62xaQMlltlUszFUNvbdIN4sO4EaLn2C1/LePUlQHWKZs2DCUbG6JOM4= 00000003.example.test. 3600 IN NSEC3 1 0 5 CC 00000004 A RRSIG 00000003.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. E0K4skeGIEfxlxHkJRBoES23n95OYtRz8KIvbcCHTXYCuM+CKnKtTCdVtgDYcx2IdyvXNDTaoylNpOAJ4IGLYNbCTCeIScQdTSB8meqDV/nFvlARcgz6ptCwi6gRoe4xpQ7T1v/h6/MFKr5BDqwFk2tDtz21Bpf8NoMLLPWIjw8= 00000004.example.test. 3600 IN NSEC3 1 0 5 DD 00000005 A RRSIG 00000004.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. yX+fvu905NpBGT0YFUtG0K/qzV4znlqNwAfIvblEW6GEanU5tiolunXXi1QYSfn8AbsPzokADW2xfGDbdMDR2FEbv7SXwoO1iQX6Yh0Sgyr8EGsUz8fLCcpZS+hovZX421RePnZkqQBY9LESeDdDpfvuxQTrh4ILSYxTSdKyBgg= 00000005.example.test. 3600 IN NSEC3 1 0 5 EE 00000006 A RRSIG 00000005.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. REolHghL+AZ46rpw+e7RwfBzPC9O6RyXnfvM4JSBfxw2J0+b7uvRoK83CHEbvkPDDgPJR8N74H1OtvRL4EkifKR5Vr11VLUDcJmXYTNP2mmlA0rwsC625cGVdZzuJjK2bvva2Cnu5vdQvjFLBPn2LVb2rxlkXeEToAQNDJMhNHo= 00000006.example.test. 3600 IN NSEC3 1 0 5 11 00000007 A RRSIG 00000006.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. V/7Yv/HdEmfHr2hGUuzoEm9/ovRxQOgeiiOVWL4S2h0r+PDd2XlpnCvS4E+fJhNsY+xGhtrPRTJTjJjxfF2r8AxcXW0Wbf6ZdPZliAAFuIK/brX6T6ReMrNq8dmEiHqg92y66Ff+aDTIdL1ufMJ+JoaygsbPghFPkD61kjs6GMs= 00000007.example.test. 3600 IN NSEC3 1 0 5 22 00000008 A RRSIG 00000007.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. gh7itP+B2Aa+S/iXkCo5lLzHY5OvW2VzkmnZ9kmezlXlJA7LkUUcPj33nCk+lY7Bvno1SEcQAYi9tCHegMsqh/RZg5gmRKMN3sn2ob2P7vbXzNiFCPpXdzHAzsmLwR61MqMPtT7gNNajKecoTM0/VkRht3J1aJJxsrmuGXyu3oM= 00000008.example.test. 3600 IN NSEC3 1 0 5 33 00000009 A RRSIG 00000008.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. qVQ4/COf1vEtswdtl8NvcZWX9otn4cjYWvVrx8Y9XbvPnboIOTrKpuej16wo6k6ak6IBBOQkIK4KDIP3iHNBlZQsxTUoaxb7EyNQ/Fkou3HNkJuf3VAUM2d/UhCmKpx5EPbmY5WQ7erDuRGMSIHYivjPOsSuLhfpcc8/jtHDcRI= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ccc.parcel.example.test. IN A SECTION ANSWER ccc.parcel.example.test. IN A 1.2.3.7 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ddd.parcel.example.test. IN A SECTION ANSWER ddd.parcel.example.test. IN A 1.2.3.8 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION eee.parcel.example.test. IN A SECTION ANSWER eee.parcel.example.test. IN A 1.2.3.9 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION fff.parcel.example.test. IN A SECTION ANSWER fff.parcel.example.test. IN A 1.2.3.10 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ggg.parcel.example.test. IN A SECTION ANSWER ggg.parcel.example.test. IN A 1.2.3.11 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION hhh.parcel.example.test. IN A SECTION ANSWER hhh.parcel.example.test. IN A 1.2.3.12 ENTRY_END RANGE_END ; ns.example.test. RANGE_BEGIN 270 300 ADDRESS 1.2.3.4 ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION parcel.example.test. IN DS SECTION ANSWER SECTION AUTHORITY example.test. 3600 IN SOA ns.example.test. host.example.test. 20301 3600 1800 604800 3600 example.test. 3600 IN RRSIG SOA 8 2 3600 20201116135527 20201019135527 55567 example.test. 2UUkScBAN37fJpSrelhE8DotKvmOzj3q9wicaanCIaCv95DE4nQnePih5B+ek3FIRjB/Uv2+z4Ro5Uxy94XAnlK0rCkDLSa0U9U7KP0ytc88sevO0x1SCPAMoZoJO6JqHkv42pdh54WSz+Zb/D8npY0j/tksHe/uX+VQnMymgb8= 00000001.example.test. 3600 IN NSEC3 1 0 5 AA 00000002 A RRSIG 00000001.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. e8JQpXALnirEp55SDzotEv/nBj1K+Rnx8BgNQQ74grKFHcrTx1xcJo2uhD5JSJk+5A11oWRcnzYwGYZyzjw4h9UBz7XZQogcvL5igPGbvtK71DiPnIMMj7aN/7yl/Q2gdkCqr0bBi2ZWO6AzGG90K33IlW2ZrttdaDzTNsF43rk= 00000002.example.test. 3600 IN NSEC3 1 0 5 BB 00000003 A RRSIG 00000002.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. b0jlxmbQqwGxB7jkiMW3PeEnvv9kBYHQ24qCgDXqpeqMfQxpEoXrSxmipI3JitV2FZqvNw+mJJ7Wy5kEGLvOqHJhxcPlbOJjVH2UDhWVNh0fR6UFGwZb62xaQMlltlUszFUNvbdIN4sO4EaLn2C1/LePUlQHWKZs2DCUbG6JOM4= 00000003.example.test. 3600 IN NSEC3 1 0 5 CC 00000004 A RRSIG 00000003.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. E0K4skeGIEfxlxHkJRBoES23n95OYtRz8KIvbcCHTXYCuM+CKnKtTCdVtgDYcx2IdyvXNDTaoylNpOAJ4IGLYNbCTCeIScQdTSB8meqDV/nFvlARcgz6ptCwi6gRoe4xpQ7T1v/h6/MFKr5BDqwFk2tDtz21Bpf8NoMLLPWIjw8= 00000004.example.test. 3600 IN NSEC3 1 0 5 DD 00000005 A RRSIG 00000004.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. yX+fvu905NpBGT0YFUtG0K/qzV4znlqNwAfIvblEW6GEanU5tiolunXXi1QYSfn8AbsPzokADW2xfGDbdMDR2FEbv7SXwoO1iQX6Yh0Sgyr8EGsUz8fLCcpZS+hovZX421RePnZkqQBY9LESeDdDpfvuxQTrh4ILSYxTSdKyBgg= 00000005.example.test. 3600 IN NSEC3 1 0 5 EE 00000006 A RRSIG 00000005.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. REolHghL+AZ46rpw+e7RwfBzPC9O6RyXnfvM4JSBfxw2J0+b7uvRoK83CHEbvkPDDgPJR8N74H1OtvRL4EkifKR5Vr11VLUDcJmXYTNP2mmlA0rwsC625cGVdZzuJjK2bvva2Cnu5vdQvjFLBPn2LVb2rxlkXeEToAQNDJMhNHo= 00000006.example.test. 3600 IN NSEC3 1 0 5 11 00000007 A RRSIG 00000006.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. V/7Yv/HdEmfHr2hGUuzoEm9/ovRxQOgeiiOVWL4S2h0r+PDd2XlpnCvS4E+fJhNsY+xGhtrPRTJTjJjxfF2r8AxcXW0Wbf6ZdPZliAAFuIK/brX6T6ReMrNq8dmEiHqg92y66Ff+aDTIdL1ufMJ+JoaygsbPghFPkD61kjs6GMs= 00000007.example.test. 3600 IN NSEC3 1 0 5 22 00000008 A RRSIG 00000007.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. gh7itP+B2Aa+S/iXkCo5lLzHY5OvW2VzkmnZ9kmezlXlJA7LkUUcPj33nCk+lY7Bvno1SEcQAYi9tCHegMsqh/RZg5gmRKMN3sn2ob2P7vbXzNiFCPpXdzHAzsmLwR61MqMPtT7gNNajKecoTM0/VkRht3J1aJJxsrmuGXyu3oM= 00000008.example.test. 3600 IN NSEC3 1 0 5 33 00000009 A RRSIG 00000008.example.test. 3600 IN RRSIG NSEC3 8 3 3600 20201116135527 20201019135527 55567 example.test. qVQ4/COf1vEtswdtl8NvcZWX9otn4cjYWvVrx8Y9XbvPnboIOTrKpuej16wo6k6ak6IBBOQkIK4KDIP3iHNBlZQsxTUoaxb7EyNQ/Fkou3HNkJuf3VAUM2d/UhCmKpx5EPbmY5WQ7erDuRGMSIHYivjPOsSuLhfpcc8/jtHDcRI= ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ccc.parcel.example.test. IN A SECTION ANSWER ccc.parcel.example.test. IN A 1.2.3.7 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ddd.parcel.example.test. IN A SECTION ANSWER ddd.parcel.example.test. IN A 1.2.3.8 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION eee.parcel.example.test. IN A SECTION ANSWER eee.parcel.example.test. IN A 1.2.3.9 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION fff.parcel.example.test. IN A SECTION ANSWER fff.parcel.example.test. IN A 1.2.3.10 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION ggg.parcel.example.test. IN A SECTION ANSWER ggg.parcel.example.test. IN A 1.2.3.11 ENTRY_END ENTRY_BEGIN MATCH opcode qtype qname ADJUST copy_id REPLY QR AA NOERROR SECTION QUESTION hhh.parcel.example.test. IN A SECTION ANSWER hhh.parcel.example.test. IN A 1.2.3.12 ENTRY_END RANGE_END STEP 10 QUERY ADDRESS 10.0.0.1 ENTRY_BEGIN REPLY RD DO SECTION QUESTION www.example.test. IN A ENTRY_END ; the DNSSEC chain is set up, in cache. STEP 20 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA AD DO NOERROR SECTION QUESTION www.example.test. IN A SECTION ANSWER www.example.test. IN A 1.2.3.4 www.example.test. 3600 IN RRSIG A 8 3 3600 20201116135527 20201019135527 55567 example.test. sbK517uW0iiO1FbJ+rCSrISg6RoIsXAFmd8NgF9mERAefkiVYTjUxdm4USccVg4Xwig9S14yANFPXY1QQbTxx25mcOdw4wyJUjGZosaIYS2DSTsAnDSgEOHPiEnYM84/UCjfWY54P4SFnCx8esaZfSdMu6YG+d3CxR1wJGloju4= ENTRY_END ; The answer RANGE is stopped during this time, so the two queries ; are both filed before unbound can get upstream answers. STEP 30 QUERY ADDRESS 10.0.0.1 ENTRY_BEGIN REPLY RD DO SECTION QUESTION aaa.parcel.example.test. IN A ENTRY_END STEP 40 QUERY ADDRESS 10.0.0.2 ENTRY_BEGIN REPLY RD DO SECTION QUESTION bbb.parcel.example.test. IN A ENTRY_END ; The RANGE starts again, for example.test STEP 50 TRAFFIC STEP 60 TRAFFIC ; The long NSEC3 RRSIGs are suspended from the validator, ; with a timer that waits, about 0.040 sec. STEP 61 TIME_PASSES ELAPSE 0.01 ; now fire off the other queries. ; while the parcel.example.test. DS query has finished up, ; but aaa.parcel.example.test and bbb.parcel.example exist, and the ; validator suspend timer is set to happen (in a while). ; new queries come in. STEP 100 QUERY ADDRESS 10.0.0.1 ENTRY_BEGIN REPLY RD DO SECTION QUESTION ccc.parcel.example.test. IN A ENTRY_END STEP 110 QUERY ADDRESS 10.0.0.2 ENTRY_BEGIN REPLY RD DO SECTION QUESTION ddd.parcel.example.test. IN A ENTRY_END STEP 120 QUERY ADDRESS 10.0.0.3 ENTRY_BEGIN REPLY RD DO SECTION QUESTION eee.parcel.example.test. IN A ENTRY_END STEP 130 QUERY ADDRESS 10.0.0.4 ENTRY_BEGIN REPLY RD DO SECTION QUESTION fff.parcel.example.test. IN A ENTRY_END STEP 140 QUERY ADDRESS 10.0.0.5 ENTRY_BEGIN REPLY RD DO SECTION QUESTION ggg.parcel.example.test. IN A ENTRY_END STEP 150 QUERY ADDRESS 10.0.0.6 ENTRY_BEGIN REPLY RD DO SECTION QUESTION hhh.parcel.example.test. IN A ENTRY_END ; validation suspend timer from aaa.parcel and bbb.parcel fires STEP 261 TIME_PASSES ELAPSE 0.1 STEP 262 TIME_PASSES ELAPSE 0.1 STEP 263 TIME_PASSES ELAPSE 0.2 STEP 264 TIME_PASSES ELAPSE 0.4 STEP 265 TIME_PASSES ELAPSE 0.4 STEP 266 TIME_PASSES ELAPSE 0.4 STEP 267 TIME_PASSES ELAPSE 0.4 ; now ordinary traffic flows again STEP 270 TRAFFIC ; and timers elapse STEP 271 TIME_PASSES ELAPSE 0.4 STEP 272 TIME_PASSES ELAPSE 0.4 STEP 273 TIME_PASSES ELAPSE 0.4 STEP 274 TIME_PASSES ELAPSE 0.4 STEP 275 TIME_PASSES ELAPSE 0.4 STEP 276 TIME_PASSES ELAPSE 0.4 STEP 277 TIME_PASSES ELAPSE 0.4 STEP 280 TRAFFIC STEP 300 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION aaa.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 310 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION bbb.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 320 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION ccc.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 330 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION ddd.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 340 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION eee.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 350 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION fff.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 360 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION ggg.parcel.example.test. IN A SECTION ANSWER ENTRY_END STEP 370 CHECK_ANSWER ENTRY_BEGIN MATCH all REPLY QR RD RA DO SERVFAIL SECTION QUESTION hhh.parcel.example.test. IN A SECTION ANSWER ENTRY_END SCENARIO_END @ 1.1.1.1 log @Import unbound-1.26.1 (previous was unbound-1.25.1) Unbound 1.26.1 ============== This release has a number of security fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-77860, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-81634, CVE-2026-81642, CVE-2026-82717, CVE-2026-82720 and CVE-2026-85501. Bug Fixes Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber, for the report. Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report. Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, for the report. In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue. Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report. Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, for the report. Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for the report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report. Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report. Unbound 1.26.0 ============== This release has some features and a number of bug fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . The certificates for the root key are updated. The icannbundle.pem file is updated with the public keys for 2009 to 2029 and for 2025 to 2045. This is available in the unbound-anchor tool. With the -l option unbound-anchor lists the builtin key and cert that it has. The updated certificates are valid for a longer time. With -c the icannbundle.pem file can be given from the commandline. Then unbound-anchor does not use the builtin certificates. And this allows the update of the certificate file without a change in unbound-anchor. The ipsecmod module is changed, that the script, for the hook, has to start with a line like #!/bin/sh. The file is executed with execv, and not any longer with system, so that it is better for security. It is an in-depth protection against possible quotation and buffer failures. The server continues to start if secondary zones, for auth zones, fail to load from zonefile. To protects against malformed content in the zonefiles, and the server continues to serve, and attempt to fetch new updates for the zone. Also for primary auth zones, if the zonefile does not exist, the server continues to start up. This makes the server start more easily. Secondary zones are no longer allowed to have a $INCLUDE in the zonefile. That is for safety, for what file is chosen. The server drops out-of-zone content from auth zones when they are read, those records are not supposed to be part of the auth zone. The primary hostname that is transferred from, can now be a name that uses CNAME(s). The options max-transfer-size and max-transfer-time can be used to limit the amount of size and time that auth-zone transfers use. The default is disabled, that is backwards compatible. The unbound-control command local_data_remove is overloaded to also work to be able to remove specific records. Specify the record with its details to remove it. Apart from the local-zone type block_a, that denies A lookups, there is now also block_aaaa, it denies AAAA lookups. The local zone types block_a_wdata and block_aaaa_wdata can be used to also have local-data, that is served, if it is not there, like transparent, it lookups recursively, or denies the particular type from lookup. These are helpful in IPv4 with IPv6 deployment situations, as it forces applications to not use a particular transport. With the changes to respip and RPZ processing that make the filters apply equally after dns64, so that dns64 does not bypass the filter, the new local-zone types can be used to apply denial of a particular transport. Features Update icannbundle.pem certificates in unbound-anchor. It has the public keys for 2009 to 2029 and for 2025 to 2045. Fix to add max-transfer-size and max-transfer-time that limit auth-zone and rpz transfer amount and time taken. Default is disabled. This hardens against unbounded transfers. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Merge #1087: Overload local_data_remove to support removing specific records. Merge #1433 from jisakiel: Add new static zone type block_aaaa to suppress AAAA queries. Fix #1477: respip + dns64: dns64 uses A records modified by respip instead of original A records. Adds local-zone types block_a_wdata and block_aaaa_wdata, that are like block_a and block_aaaa, and uses local-data if present. Bug Fixes Fix windows 64bit build for libssp dependency. iana portlist updated. Fix for Heap Out-of-Bounds Write via size_t-to-int Truncation in setup_if() - outside_network_create(). This fixes that large values for num_ports do not overflow and create invalid references after integer truncation. Thanks to Karnakar Reddy (@@karnakarreddi) for the report. Fix to clean up log ids after a failure to start a worker thread. Fix to relax assertions after the TTL 0 handling change. This relaxes an assertion in cachedb (it fails instead), and for packet_rrset_copy_region. Fix comment and verbose logging for EDNS fallback buffer size. Fix man page entry for so-sndbuf, it is for responses sent out. Fix val_find_DS for robustness, to check the result of packet_rrset_copy_region before using it. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix that for dns64 answers, the AAAA query is checked to be DNSSEC validated, when DNSSEC is enabled. This improves the RFC6147 conformance of Unbound. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. In addition, thanks to Qifan Zhang, Palo Alto Networks, for reporting it. Fix for allocation-failure hardening of rrset cache wildcard storage and canonical NSEC owner replacement. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix DNSSEC validation with libnettle for noncanonical RSA DNSKEYs with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix DNSKEY size calculation for noncanonical RSA DNSKEYs with leading zeroes for n. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix for mixed class referrals, the resolver uses the query class. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Unit test for CVE-2026-33278. Unit test for CVE-2026-42944. Unit test for CVE-2026-42959. Unit test for CVE-2026-40622. Unit test for CVE-2026-42960. Fix in depth for serve-expired responses from cachedb, that it does not store bogus. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix lame server detection, for selfpointed glue records. Thanks to Shuhan Zhang, Dan Li, and Baojun Liu from Tsinghua University for the report. Fix cleaning up DoH session. The same query can be on multiple streams in a session. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix for signed same-owner CNAME and ordinary RRset responses. Thanks to Xin Wang and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix for mesh new client and mesh new callback to rollback the added address, tcp mesh state and callback when there is a failure to initialize. This fixes the mesh accounting of reply addresses. Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for the report Fix for autotrust state-file line overflow, that can give hold-down bypass. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to limit the DSNS per-label walk in the iterator. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that the ratelimit is decremented on successful referrals. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that msgencode insert_query has the correct assertion, for a local_alias. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to reset the tcp-timeout before applying a load based reduction. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to decrement the per-netblock tcp connection limits, so it keeps usable. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix manual to document ratelimit, that it is for target nameservers for a domain, and keeps queries limited. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix, in depth, for respip rewrite of dns64 responses. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that dns64 with subnetcache does not write ECS scoped answers to global cache. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix ipset module for name too long checks, race conditions on local name buffer, and for socket close race condition. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that validator caps number of ANY RRsets it can validate, and the wait timer is shortened. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix analyzer warning in mesh_new_client. Fix #1457: race condition causes segfault when starting threads. Fix header_seen detection for trust anchor files, so that it detects the id line. Fix unit test to check for new icannbundle.pem. Fix const as reported by newest compiler warnings. Fix that the processing of class responses does not have a heap use-after-free. That could happen if at least two distinct classes are configured for resolution. Thanks to Qifan Zhang, Palo Alto Networks for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this. Fix negative cache to work with NSEC3 records without salt. Thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for the report. Fix parse of svcbparam ech, it had incorrect length. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix that quotation and escaping works the same in auth-zone url content, as in the zonefile read. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix ipset module to use larger domain name buffers, and check buffer lengths. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix PROXYv2 header read and consume, it checks the header size. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix negative cach... Unbound 1.25.2 ============== This release has a number of security fixes. The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026: User ID: NLnet Labs releases signing key G2 releases@@nlnetlabs.nl Key ID: A144 323D EAAC DF45 Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45 The key is available from https://nlnetlabs.nl/signing-keys . This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-14586, CVE-2026-32665, CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621, CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045, CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251, CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708, CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991, CVE-2026-56416 and CVE-2026-56444. Bug Fixes Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments. Thanks to Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for the report. Fix CVE-2026-32665, Remote DNS-over-QUIC denial of service due to quic-size budget bypass. Thanks to N0zoM1z0 (https://github.com/N0zoM1z0) for the report. In addition, thanks to Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for also reporting this issue. In addition, thanks to Qifan Zhang, Palo Alto Networks, for also reporting this issue. In addition, thanks to Xuanchao Xie, for also reporting this issue. Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Trung Nguyen (@@everping) of CyStack, for also reporting this issue. Fix CVE-2026-41637, Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44621, Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via RRSIG.labels manipulation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-46582, A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation restarts. Thanks to Kunjie Shang, University of Science and Technology of China, for the report. Fix CVE-2026-50046, Possible heap use-after-free in an error path when a DoT forwarded query is jostled out. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50248, BOGUS configured primary hostname accepted for XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-50252, Possible cache poisoning attack by mapping source port population per thread. Thanks to Inbal Schussheim and Amit Klein, Hebrew University, for the report. Fix CVE-2026-52863, Memory corruption could lead to crash and denial of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-54478, DNS Cookie bypass when combined with proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55708, Privacy/configuration issue when adding local data in views through 'unbound-control'. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this issue. Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xuanchao Xie, for also reporting this issue. Fix CVE-2026-56416, Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix CVE-2026-56444, Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also reporting this issue. In addition, thanks to Haruki Oyama (Waseda University), for also reporting this issue. @ text @@