Home / mailingsPDF  

[SECURITY] [DSA 6507-1] unbound security update

Posted on 19 September 2026
Debian Security Advisory

5B-------------------------------------------------------------------------
Debian Security Advisory DSA-6507-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
September 19, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : unbound
CVE ID : CVE-2026-14586 CVE-2026-32665 CVE-2026-40622 CVE-2026-40691
CVE-2026-41637 CVE-2026-42955 CVE-2026-44621 CVE-2026-44687
CVE-2026-44690 CVE-2026-46582 CVE-2026-50045 CVE-2026-50046
CVE-2026-50243 CVE-2026-50248 CVE-2026-50251 CVE-2026-50252
CVE-2026-52863 CVE-2026-54478 CVE-2026-55708 CVE-2026-55717
CVE-2026-55973 CVE-2026-55990 CVE-2026-55991 CVE-2026-56416
CVE-2026-56444 CVE-2026-77860 CVE-2026-77955 CVE-2026-78227
CVE-2026-80225 CVE-2026-81634 CVE-2026-81642 CVE-2026-82717
CVE-2026-82720 CVE-2026-85501

Multiple security vulnerabilities were discovered in Unbound, a validating,
recursive, caching DNS resolver, which could result in denial of service,
cache poisoning, DNS cookie bypass or potentially the execution of
arbitrary code.

For the stable distribution (trixie), these problems have been fixed in
version 1.26.1-0+deb13u1.

We recommend that you upgrade your unbound packages.

For the detailed security status of unbound please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/unbound

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP