unbound: updated to 1.26.0
1.26.0
Features
Update icannbundle.pem certificates in unbound-anchor. It has the public keys for 2009 to 2029 and for 2025 to 2045.
Fix to add `max-transfer-size` and `max-transfer-time` that limit auth-zone and rpz transfer amount and time taken. Default is disabled. This hardens against unbounded transfers. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Merge 1087: Overload `local_data_remove` to support removing specific records.
Merge 1433 from jisakiel: Add new static zone type block_aaaa to suppress AAAA queries.
Fix 1477: respip + dns64: dns64 uses A records modified by respip instead of original A records. Adds local-zone types block_a_wdata and block_aaaa_wdata, that are like block_a and block_aaaa, and uses local-data if present.
p5-Net-CIDR-Set: update to 0.23.
0.23 2026-08-11 20:08:42+01:00 Europe/London
[Security]
- Fix an unbounded IPv6 netmask prefix length (CVE-2026-19566)
0.22 2026-06-13 14:44:25+01:00 Europe/London
[Toolchain]
- Set the static install flag
- Adjusted build prerequisites to be recommended instead of required.
- Sign distribution with SigStore.
[Tests]
- Added author tests.
- Update minimum prereqs for some tests.
py-dnsdiag: updated to 2.9.4
2.9.4
Fixed
fix: reset shutdown flag at the start of each CLI invocation
fix(dnsping): validate source IP address family against -4/-6 flag
fix(dnsping): fix variable shadowing and div-by-zero in stats
fix(dnsping): reuse TCP connection for fixed source port queries
py-duckdb: Pass CMAKE_BUILD_PARALLEL_LEVEL.
Any package that uses py-scikit-build-core to build does not honour MAKE_JOBS.
Some packages use make and so are single threaded, but some like duckdb use
ninja, and that defaults to ncores+2(!) per build.
On my 72-core build host, building 3 py-duckdb packages simultaneously, this is
enough to completely swamp things and cause knock-on failures that effectively
kill the bulk build.
Ideally this needs to be done in a build.mk or similar for py-scikit-build-core
but this gets us past this for now.
rsync: update to 3.5.0.
This release fixes 33 security issues found during a focused audit
of rsync's path handling and daemon protocol, a companion
daemon-protocol fuzzing pass, and reports from external researchers
-- plus several robustness hardenings. CVE IDs were assigned by
VulnCheck (CNA); the precise "introduced in" version ranges accompany
each advisory, and many are much narrower than "everything before
3.5.0". Every fix ships with a regression test in the test suite
that fails on the unfixed tree.
Full details at https://download.samba.org/pub/rsync/NEWS#3.5.0
libcdio: updated to 2.4.0
2.4.0
* Note incorrect field name `min_rate` should be called `max_rate`.
* Apply timeout in MMC command on GNU/Linux
* Fix no MMC data returned when buffer size is divisible by 256 (skr4n).
* Deprecate obscure MMC set length macros (skr4n)
* In eject programs on GNU/Linux, cdio_open needs access mode RDWR.
* More ISO field validation in RockRidge (Acts1631).
* Validate bounds in disk images reading (Acts1631).
* Validate UDF File Identifier Descriptor bounds (Acts1631).
* Change references from MMC-5 to MMC-6 Draft 2g when possible.
* At URLS for MMC6 Draft 2g and SPC-3.
* Administrivia: Error when help2man not found in maintainer mode. Otherwise warn, and tolerate builds without help2man.
* Correct the way MMC CDB allocation length values are set (skr4n).
* Correct XA attribute flags (skr4n)
- Add `*SYS` values of the XA attribute flags to represent the other/world user mode bits.
- Fix it to use the `*OTH` values instead.
[7 lines not shown]
harfbuzz: updated to 14.3.1
14.3.1
- Various fuzzing and build fixes.
- Various subsetting fixes.
- Fix AAT insertion at the end of the text.
- Fix various rendering bugs in the experimental GPU library.
- WASM shaper code can now read the user features.
py-aiohttp-remotes: mark as BROKEN
Does not build with flit_core 4.
Still looks active, so filed an upstream bug report - add link to
upstream bug report URL.