]> git.ipfire.org Git - thirdparty/unbound.git/tag
release-1.16.2
object cbed768b8ff9bfcf11089a5f1699b7e5707f1ea5
authorW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Mon, 1 Aug 2022 11:28:52 +0000 (13:28 +0200)
Unbound 1.16.2

This release fixes the novel ghost domain issues CVE-2022-30698 and
CVE-2022-30699. They were reported by Xiang Li from the Network and
Information Security Lab of Tsinghua University.

Other than that there are some bug fixes, and an option to configure the
max retransmit timeout, infra-cache-max-rtt. If left at default it does
not make any change.

Features
- Merge #718: Introduce infra-cache-max-rtt option to config max
  retransmit timeout.

Bug Fixes
- Fix the novel ghost domain issues CVE-2022-30698 and CVE-2022-30699.
- Fix bug introduced in 'improve val_sigcrypt.c::algo_needs_missing for
  one loop pass'.
- Merge PR #668 from Cristian Rodríguez: Set IP_BIND_ADDRESS_NO_PORT on
  outbound tcp sockets.
- Fix verbose EDE error printout.
- Fix dname count in sldns parse type descriptor for SVCB and HTTPS.
- For windows crosscompile, fix setting the IPV6_MTU socket option
  equivalent (IPV6_USER_MTU); allows cross compiling with latest
  cross-compiler versions.
- Merge PR 714: Avoid treat normal hosts as unresponsive servers.
  And fixup the lock code.
- iana portlist update.
- Update documentation for 'outbound-msg-retry:'.
- Tests for ghost domain fixes.
-----BEGIN PGP SIGNATURE-----

iQJIBAABCAAyFiEE7fqj8spObrBWga+On28cLX4EX40FAmLnuPoUHHdvdXRlckBu
bG5ldGxhYnMubmwACgkQn28cLX4EX40hDA/+PyC/kug0Qve7fysnRKnYXlEhJabF
8F2JXSqHXNRNUKVaBN9EYaObSLEQPeO2O3Rsinrcg1g6lA9CmOaeWvCdYon288Th
66z5MVgP3FaEOKHVqv2FWndGIz5nhDvRenk1nlqHoa27zImkX48YrgaGtlivWqfB
m9esWnHfvriSoqmn23ImYwdpEFPnj6KJGjrASSRnU44LP9sD7sfmBoZqEYS3cdcy
Vfz0h6xZR095jlq4u4zSMC6EeZICXmGFUAtdwUiDZ/16Q5t1yeguwZEACpM8WvxJ
BavDXcUwqi62OJGWkmxpz9Kr+CNm62e4Ml8QmNC2VMh1ybe8ZEa3O8I3h7uy2ne/
uhy0IKP0f7i/X/iqRkkE0qKYybXZg/1Dl3m4uyQiJawejxbKtoD1V5wZmQe8Xsbo
SBfsRDj7AdFTWjlVqLyeNY7CVeK5QwYD1GbWeH8OJrJe43Breq0qyazSRV9IwVpE
a6lcvKPD6FQjuve8ACBOtquI5mXEPA8FG0aMDddGktj5Oc42V4nyE2UGmr+VDOmQ
5jxNAU8bAeKk1sfkRkm4o5R/ifn2rx829yq6hcdGZm3B4M6D2g7F5L5O0JYho4KC
GI+7tGcM76F9HRcFqzE7MyeoSh1KFGG122x11CsJEVio40M3jfPzvri7IIXNjuRt
FMSIrnUSWqI/eQ4=
=IEJp
-----END PGP SIGNATURE-----