]> git.ipfire.org Git - thirdparty/unbound.git/commit
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
authorW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Wed, 22 Jul 2026 08:09:26 +0000 (10:09 +0200)
committerW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Wed, 22 Jul 2026 08:09:26 +0000 (10:09 +0200)
commit01dfd2f466d383370405d8ecf939570947f3523e
tree4740736314f3f0619c782f37b596772b99665ce1
parentf157c691bbd7ac5a2b29d1bf30283cb043052e9a
- Fix CVE-2026-32665, Remote DNS-over-QUIC denial of
  service due to `quic-size` budget bypass. Thanks to N0zoM1z0
  (https://github.com/N0zoM1z0) for the report. In addition, thanks to
  Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University,
  for also reporting this issue. In addition, thanks to Qifan Zhang,
  Palo Alto Networks, for also reporting this issue. In addition,
  thanks to Xuanchao Xie, for also reporting this issue.
services/listen_dnsport.c