Hi, On Tue, Jul 21, 2026 at 03:24:15PM +0200, Ondřej Surý wrote: > Package: unbound > Version: 1.22.0-2+deb13u3 > Severity: critical > Justification: causes serious data loss > X-Debbugs-Cc: [email protected] > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > Dear Maintainer, > > I've been told by several root nameservers that version of unbound > as shipped by Debian has a serious flaw that causes unbound to double > the traffic to the root zone system endangering the whole stability > of the DNS system (the RZ operators could still cope with this, but > doubling the traffic is quite horrible). > > There has been large operator that upgraded to Debian Trixie and > enabled serve-stale and this has caused several eyebrows to raise, > and people coming to me (since they know I am DD) asking if I can > help. > > NLNetLabs had been notified, but since this is already fixed in > the upstream packages, this needs to be expeditely fixed in Debian > as this can cause instability in the DNS ecosystem. > > Please look into this as soon as possible, or ping me if you want > me to NMU unbound via security-team. I am notifying the security > team as well.
IMHO the security archive is not for such bugfixes (and as this is not a security issue in unbound), so an update via a stable-update (with a SUA advisory) seems more appropriate. See: https://wiki.debian.org/StableUpdates https://lists.debian.org/debian-stable-announce/ Regards, Salvatore

