diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch new file mode 100644 index 0000000000..1e338b1709 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch @@ -0,0 +1,58 @@ +From 8711cb40328a6fab85bebb12be0c2948c0752291 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:16:18 +0200 +Subject: [PATCH] - Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to + Qifan Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit 8d8fa4226613138f5a244a9f1a2506704e049180) + +CVE: CVE-2026-40622 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/8d8fa4226613138f5a244a9f1a2506704e049180] + +Dropped changes to the Changelog file. + +Also backport TTL_IS_EXPIRED macro introduced by commit: +https://github.com/NLnetLabs/unbound/commit/73e408f1d0792267429e9f5f89537cda61297952 + +Signed-off-by: Ankur Tyagi +--- + services/cache/rrset.c | 10 ++++++++++ + util/data/msgparse.h | 4 ++++ + 2 files changed, 14 insertions(+) + +diff --git a/services/cache/rrset.c b/services/cache/rrset.c +index 6d5c24f80..81f4e2820 100644 +--- a/services/cache/rrset.c ++++ b/services/cache/rrset.c +@@ -149,6 +149,16 @@ need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns) + if(equal && cached->ttl >= timenow && + cached->security == sec_status_bogus) + return 0; ++ /* ghost-domain: never let an NS overwrite extend lifetime ++ * past the entry it replaces, regardless of trust. */ ++ if(ns && !TTL_IS_EXPIRED(cached->ttl, timenow) && ++ newd->ttl > cached->ttl) { ++ size_t i; ++ newd->ttl = cached->ttl; ++ for(i=0; i<(newd->count+newd->rrsig_count); i++) ++ if(newd->rr_ttl[i] > newd->ttl) ++ newd->rr_ttl[i] = newd->ttl; ++ } + return 1; + } + /* o item in cache has expired */ +diff --git a/util/data/msgparse.h b/util/data/msgparse.h +index 7de4e394f..9bfe0225d 100644 +--- a/util/data/msgparse.h ++++ b/util/data/msgparse.h +@@ -98,6 +98,10 @@ extern time_t SERVE_EXPIRED_REPLY_TTL; + /** If we serve the original TTL or decrementing TTLs */ + extern int SERVE_ORIGINAL_TTL; + ++/** Check if TTL is expired. 0 TTL is considered expired. ++ * Used mainly to identify parts of the code that do this comparison. */ ++#define TTL_IS_EXPIRED(ttl, now) ((ttl) <= (now)) ++ + /** + * Data stored in scratch pad memory during parsing. + * Stores the data that will enter into the msgreply and packet result. diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 1225cb99c2..1c9a7fa489 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -16,6 +16,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42944-2.patch \ file://CVE-2026-42959.patch \ file://CVE-2026-32792.patch \ + file://CVE-2026-40622.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c"