The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
unbound: Heap overflow and crash with multiple nsid, cookie, padding EDNS options (CVE-2026-42944)
unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages (CVE-2026-42959)
unbound: Unbound DNSSEC Validator Use-After-Free via Deep Copy Pointer Overwrite Leading to DoS and Possible Remote Code Execution (CVE-2026-33278)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.