NLnet Labs reports:
This release consolidates security fixes for issues reported over
a period of time. There are fixes for:
- CVE-2026-81642: Heap buffer overflow and possible Remote Code
Execution when digesting DNSKEY.
- CVE-2026-81634: Possible heap buffer overflow during DNSSEC
canonicalization.
- CVE-2026-82717: CNAME synthesis could lead to heap corruption.
- CVE-2026-77955: Possible ZONEMD verification bypass window.
- CVE-2026-78227: Use-after-free in DoQ stream output buffer on
reset re-transmission.
- CVE-2026-80225: Possible degradation of service from continuous
queries on the same TCP/DoT connection.
- CVE-2026-82720: Use-after-free in DoH stream cleanup code path.
- CVE-2026-85501: Retrap: Novel Vulnerabilities to launch
Algorithmic Complexity Attacks on DNSSEC.
- CVE-2026-77860: ‘serve-expired’ can bypass Unbound ‘wait-limit’.