<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/net/unbound/patches, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/'/>
<updated>2026-07-31T05:55:00Z</updated>
<entry>
<title>unbound: update to 1.25.2</title>
<updated>2026-07-31T05:55:00Z</updated>
<author>
<name>Tyrel M. McQueen</name>
</author>
<published>2026-07-30T10:47:52Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=2a28bbc943cf9d02cf6f911b5598b9733d2977d3'/>
<id>urn:sha1:2a28bbc943cf9d02cf6f911b5598b9733d2977d3</id>
<content type='text'>
From upstream: 1.25.2 consolidates security fixes for issues reported over
a period of time. There are fixes for CVE-2026-14586, CVE-2026-32665,
CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621,
CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045,
CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251,
CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708,
CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991,
CVE-2026-56416 and CVE-2026-56444.

Full details at

https://github.com/NLnetLabs/unbound/releases/tag/release-1.25.2

Signed-off-by: Tyrel M. McQueen &lt;tmcqueen.materials@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.25.1</title>
<updated>2026-05-28T09:17:42Z</updated>
<author>
<name>Tyrel M. McQueen</name>
</author>
<published>2026-05-27T16:27:31Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=0270d94c31426037b9956d1bdc22104dd874d75d'/>
<id>urn:sha1:0270d94c31426037b9956d1bdc22104dd874d75d</id>
<content type='text'>
From upstream: 1.25.1 consolidates security fixes for issues
reported over a period of time. There are fixes for CVE-2026-33278,
CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622,
CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960,
CVE-2026-44390 and CVE-2026-44608.

Full details at

https://www.nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/

and

https://www.nlnetlabs.nl/news/2026/Apr/29/unbound-1.25.0-released/

Signed-off-by: Tyrel M. McQueen &lt;tmcqueen.materials@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.24.2</title>
<updated>2025-12-10T17:38:27Z</updated>
<author>
<name>Goetz Goerisch</name>
</author>
<published>2025-12-06T07:43:13Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=0ca33e71e99275e77884590006bcfc704cbcfec7'/>
<id>urn:sha1:0ca33e71e99275e77884590006bcfc704cbcfec7</id>
<content type='text'>
Fixes: Possible Domain Hijacking via promiscuous NS Records (CVE-2025-11411)
Changelog: https://www.nlnetlabs.nl/projects/unbound/download/#unbound-1-24-2
Upstream commit f6269baa605d31859f28770e01a24e3677e5f82c
https://github.com/NLnetLabs/unbound/commit/f6269baa605d31859f28770e01a24e3677e5f82c

Signed-off-by: Goetz Goerisch &lt;ggoerisch@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.24.0</title>
<updated>2025-09-29T08:43:10Z</updated>
<author>
<name>Eric Luehrsen</name>
</author>
<published>2025-09-29T04:04:12Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=7b6300227383d08301bb7407d53834a202e13d69'/>
<id>urn:sha1:7b6300227383d08301bb7407d53834a202e13d69</id>
<content type='text'>
latest upstream 09182024

Signed-off-by: Eric Luehrsen &lt;ericluehrsen@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.23.0</title>
<updated>2025-05-09T18:52:16Z</updated>
<author>
<name>Eric Luehrsen</name>
</author>
<published>2025-05-02T03:39:37Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=a0df926a01e98ad778d5db15f27e942425269306'/>
<id>urn:sha1:a0df926a01e98ad778d5db15f27e942425269306</id>
<content type='text'>
Signed-off-by: Eric Luehrsen &lt;ericluehrsen@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.22.0</title>
<updated>2024-11-10T19:24:52Z</updated>
<author>
<name>Jan Klos</name>
</author>
<published>2024-11-10T19:24:52Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=6b989e0ad520e0a71bc18d9e84a0b7b4e4e54c07'/>
<id>urn:sha1:6b989e0ad520e0a71bc18d9e84a0b7b4e4e54c07</id>
<content type='text'>
Signed-off-by: Jan Klos &lt;jan@klos.xyz&gt;
[Solve PKG_RELEASE conflict]
</content>
</entry>
<entry>
<title>unbound: update to 1.21.0</title>
<updated>2024-08-28T20:10:42Z</updated>
<author>
<name>Jan Klos</name>
</author>
<published>2024-08-24T16:05:38Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=4dd2a82c32b10c7b1a7de57f5397f1004b2c9762'/>
<id>urn:sha1:4dd2a82c32b10c7b1a7de57f5397f1004b2c9762</id>
<content type='text'>
Signed-off-by: Jan Klos &lt;jan@klos.xyz&gt;
</content>
</entry>
<entry>
<title>unbound: Update to 1.20.0</title>
<updated>2024-06-16T23:44:45Z</updated>
<author>
<name>Ryan Keane</name>
</author>
<published>2024-06-16T00:45:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=d421db0527f41ae48ecff56501de2d56217f1182'/>
<id>urn:sha1:d421db0527f41ae48ecff56501de2d56217f1182</id>
<content type='text'>
Updated 010-configure-uname.patch as source changed.
Removed 100-example-conf-in.patch as not needed any more.

Release message:

This release has a fix for the DNSBomb issue CVE-2024-33655. This has a
low severity for Unbound, since it makes Unbound complicit in targeting
others, but does not affect Unbound so much.

To mitigate the issue new configuration options are introduced.
The options discard-timeout: 1900, wait-limit: 1000
and wait-limit-cookie: 10000 are enabled by default. They limit the
number of outstanding queries that a querier can have. This limits
the reply pulse, and make Unbound less favorable for the issue.
With the config wait-limit-netblock and wait-limit-cookie-netblock
the parameters can be fine tuned for specific destinations.
More information on the attack and Unbound's mitigations are
presented further down.

Other fixes in this release are that Unbound no longer follows symlinks
when truncating the pidfile. Unbound also does not chown the pidfile,
this is for safety reasons. There are also a number of fixes for RPZ, in
handling CNAMEs. There is a memory leak fix for the edns client subnet
cache. For DNSSEC validation a case is fixed when the query is of type
DNAME. The unbound-anchor program is fixed to first write to a temporary
file, before replacing the original. This handles disk full situations,
and because of it unbound-anchor needs permission to create that file,
in the same directory as the original file. There is also a fix for
IP_DONTFRAG, to disable fragmentation instead of the opposite.

The option cache-min-negative-ttl can be used to set the minimum TTL
for negative responses in the cache. It complements existing options to
set the maximum ttl for negative responses and to set the minimum and
maximum ttl but not specifically for negative responses.

The option cachedb-check-when-serve-expired option makes Unbound use
cachedb to check for expired responses, when serve-expired is enabled,
and cachedb is used. It is enabled by default.

The -q option for unbound-checkconf can be added to silence it when
there are no errors.

Signed-off-by: Ryan Keane &lt;the.ra2.ifv@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: update to 1.19.3</title>
<updated>2024-03-18T20:26:51Z</updated>
<author>
<name>Jan Klos</name>
</author>
<published>2024-03-18T20:26:51Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=558cbcac4698d58b11be23f954a7f64a296ab593'/>
<id>urn:sha1:558cbcac4698d58b11be23f954a7f64a296ab593</id>
<content type='text'>
Signed-off-by: Jan Klos &lt;jan@klos.xyz&gt;
</content>
</entry>
<entry>
<title>unbound: update to latest upstream release version 1.19.1</title>
<updated>2024-02-18T18:30:22Z</updated>
<author>
<name>S. Brusch</name>
</author>
<published>2024-02-14T12:37:59Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=35ba14e50c6c90b3cc32538573d02a3b4f5b9184'/>
<id>urn:sha1:35ba14e50c6c90b3cc32538573d02a3b4f5b9184</id>
<content type='text'>
Maintainer: @EricLuehrsen
Fixes: CVE-2023-50387, CVE-2023-50868
Release notes: https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
Run tested: BPi-R3, mediatek/filogic, OpenWrt 23.05.2
Signed-off-by: S. Brusch &lt;ne20002@gmx.ch&gt;
</content>
</entry>
</feed>
