From: W.C.A. Wijngaards Date: Thu, 23 Jul 2026 08:01:10 +0000 (+0200) Subject: - Updated credits for Xuanchao Xie in 22 july changelog. X-Git-Tag: release-1.26.0rc1~23 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=22e2c5b6d177d786e617973aac3d63b48e7e0c55;p=thirdparty%2Funbound.git - Updated credits for Xuanchao Xie in 22 july changelog. --- diff --git a/doc/Changelog b/doc/Changelog index 748823d3e..f88b813ad 100644 --- a/doc/Changelog +++ b/doc/Changelog @@ -1,3 +1,6 @@ +23 July 2026: Wouter + - Updated credits for Xuanchao Xie in 22 july changelog. + 22 July 2026: Wouter - Release tag for 1.25.2, with the security commits: - Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure @@ -10,7 +13,9 @@ Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for also reporting this issue. In addition, thanks to Qifan Zhang, Palo Alto Networks, for also reporting this issue. In addition, - thanks to Xuanchao Xie, for also reporting this issue. + thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue of the + University of Science and Technology of China (USTC), for also + reporting this issue. - Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Trung Nguyen (@everping) of CyStack, for also reporting @@ -74,7 +79,8 @@ - Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xuanchao Xie, - for also reporting this issue. + Lutong Chen, and Kaiping Xue of the University of Science and + Technology of China (USTC), for also reporting this issue. - Fix CVE-2026-56416, Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name. Thanks to Qifan Zhang, Palo Alto Networks, for the report.