<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git/meta-networking/recipes-support/unbound, branch scarthgap</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=scarthgap</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=scarthgap'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2026-04-13T07:10:21+00:00</updated>
<entry>
<title>unbound: Fix CVE-2025-11411</title>
<updated>2026-04-13T07:10:21+00:00</updated>
<author>
<name>Jackson James</name>
<email>jackson.james9803@gmail.com</email>
</author>
<published>2026-04-10T06:41:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=fc30bb5eedfa89070a112425bcf8423a7b2aa998'/>
<id>urn:sha1:fc30bb5eedfa89070a112425bcf8423a7b2aa998</id>
<content type='text'>
Backport complete patch to fix CVE-2025-11411

The existing scarthgap patch is a partial backport with hardcoded logic,
causing incorrect behavior and ptest failures. Backport the full upstream
fix along with the follow-up patch to ensure correct functionality.

Add below patch to fix
0001-CVE-2025-11411-1.patch
0002-CVE-2025-11411-2.patch

Signed-off-by: Jackson James &lt;jacksonj2@kpit.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: Fix CVE-2025-5994</title>
<updated>2026-01-12T02:42:27+00:00</updated>
<author>
<name>Naman Jain</name>
<email>nmjain23@gmail.com</email>
</author>
<published>2025-11-04T09:52:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=30dafc39583af496a300155620efd0275c79f25b'/>
<id>urn:sha1:30dafc39583af496a300155620efd0275c79f25b</id>
<content type='text'>
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been
discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is
also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND
configured to send ECS information along with queries to upstream name servers

CVE: CVE-2025-5994

Signed-off-by: Naman Jain &lt;namanj1@kpit.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: patch CVE-2024-43168</title>
<updated>2025-12-17T06:15:23+00:00</updated>
<author>
<name>Ankur Tyagi</name>
<email>ankur.tyagi85@gmail.com</email>
</author>
<published>2025-12-16T07:15:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=788904cef140e7dea251c24747a36e232d773f06'/>
<id>urn:sha1:788904cef140e7dea251c24747a36e232d773f06</id>
<content type='text'>
Details https://nvd.nist.gov/vuln/detail/CVE-2024-43168

Signed-off-by: Ankur Tyagi &lt;ankur.tyagi85@gmail.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: patch CVE-2024-43167</title>
<updated>2025-12-17T06:15:22+00:00</updated>
<author>
<name>Ankur Tyagi</name>
<email>ankur.tyagi85@gmail.com</email>
</author>
<published>2025-12-16T07:15:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=1876b4656d6d3f210f4a3cd806db0ef9a6755eab'/>
<id>urn:sha1:1876b4656d6d3f210f4a3cd806db0ef9a6755eab</id>
<content type='text'>
Details https://nvd.nist.gov/vuln/detail/CVE-2024-43167

Signed-off-by: Ankur Tyagi &lt;ankur.tyagi85@gmail.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: fix SRC_URI</title>
<updated>2025-11-12T06:08:29+00:00</updated>
<author>
<name>Gyorgy Sarvari</name>
<email>skandigraun@gmail.com</email>
</author>
<published>2025-11-09T16:00:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=6eb226f7c5bf9bc5dd5cc05adf9a85c1180d1e0d'/>
<id>urn:sha1:6eb226f7c5bf9bc5dd5cc05adf9a85c1180d1e0d</id>
<content type='text'>
The branch used in the SRC_URI got deleted, and the used revision is
detached from all branches. Use nobranch tag in the SRC_URI to avoid
fetching failures.

Signed-off-by: Gyorgy Sarvari &lt;skandigraun@gmail.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: patch CVE-2024-33655 and CVE-2025-11411</title>
<updated>2025-11-12T05:44:56+00:00</updated>
<author>
<name>Patrick Vogelaar</name>
<email>patrick.vogelaar@belden.com</email>
</author>
<published>2025-11-02T21:33:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=d9c8972cb71a85ce6dfcfce55477937ea954b1ce'/>
<id>urn:sha1:d9c8972cb71a85ce6dfcfce55477937ea954b1ce</id>
<content type='text'>
For CVE-2024-33655 applied patch [1] mentioned in [2].
For CVE-2025-11411 applied minimal patch [3] mentioned in [4]. (Slightly
adjustments were required to apply properly)

[1] https://nlnetlabs.nl/downloads/unbound/patch_CVE-2024-33655.diff
[2] https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-33655.txt
[3] https://nlnetlabs.nl/downloads/unbound/patch_CVE-2025-11411.diff
[4] https://www.nlnetlabs.nl/downloads/unbound/CVE-2025-11411.txt

Signed-off-by: Patrick Vogelaar &lt;patrick.vogelaar@belden.com&gt;
Signed-off-by: Anuj Mittal &lt;anuj.mittal@oss.qualcomm.com&gt;
</content>
</entry>
<entry>
<title>unbound: Fix CVE-2024-8508</title>
<updated>2025-03-08T00:40:44+00:00</updated>
<author>
<name>Virendra Thakur</name>
<email>virendrak@kpit.com</email>
</author>
<published>2025-03-04T09:12:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=454cc113175e42d803fe09d5a6c495c369b5a68a'/>
<id>urn:sha1:454cc113175e42d803fe09d5a6c495c369b5a68a</id>
<content type='text'>
Malicious upstreams responses with very large RRsets can cause Unbound
to spend a considerable time applying name compression to downstream
replies. This can lead to degraded performance and eventually denial of
service in well orchestrated attacks.

Reference: https://nvd.nist.gov/vuln/detail/cve-2024-8508

Signed-off-by: Virendra Thakur &lt;virendrak@kpit.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: upgrade 1.19.1 -&gt; 1.19.3</title>
<updated>2024-04-07T15:36:35+00:00</updated>
<author>
<name>Beniamin Sandu</name>
<email>beniaminsandu@gmail.com</email>
</author>
<published>2024-04-05T15:06:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=880f80650080a12c1eef94e6205c5157057904e1'/>
<id>urn:sha1:880f80650080a12c1eef94e6205c5157057904e1</id>
<content type='text'>
Includes security fixes for:
CVE-2024-1931 - Loop with Unreachable Exit Condition ('Infinite Loop')

Full release notes:
https://github.com/NLnetLabs/unbound/releases/tag/release-1.19.3

Signed-off-by: Beniamin Sandu &lt;beniaminsandu@gmail.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: upgrade 1.19.0 -&gt; 1.19.1</title>
<updated>2024-02-20T16:46:27+00:00</updated>
<author>
<name>Wang Mingyu</name>
<email>wangmy@fujitsu.com</email>
</author>
<published>2024-02-20T08:54:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=2adbf07ec1ffa08cb04e47907fa4b385edefed98'/>
<id>urn:sha1:2adbf07ec1ffa08cb04e47907fa4b385edefed98</id>
<content type='text'>
Signed-off-by: Wang Mingyu &lt;wangmy@fujitsu.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
<entry>
<title>unbound: upgrade 1.18.0 -&gt; 1.19.0</title>
<updated>2023-11-15T20:58:37+00:00</updated>
<author>
<name>Beniamin Sandu</name>
<email>beniaminsandu@gmail.com</email>
</author>
<published>2023-11-15T20:45:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=24e6bcb3759f6dc331a6716a12124e6cfaa72c0a'/>
<id>urn:sha1:24e6bcb3759f6dc331a6716a12124e6cfaa72c0a</id>
<content type='text'>
Full changelog: https://github.com/NLnetLabs/unbound/releases/tag/release-1.19.0

Signed-off-by: Beniamin Sandu &lt;beniaminsandu@gmail.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
</content>
</entry>
</feed>
