Skip to content

Refresh OpenSSL packages in the Unbound image #1736

Description

@sbaum1994

Problem

nvcf-unbound:0.10.2 contains libssl3t64 and openssl-provider-fips version 3.5.6-1~deb13u1. The same 18 advisories are reported against both packages, for 36 occurrences total: 6 Critical and 30 High.

Critical (per package): CVE-2026-34182, CVE-2026-63073, CVE-2026-75803

High (per package): CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-34180, CVE-2026-34181, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445, CVE-2026-45447, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-7383, CVE-2026-9076

Recorded fixed package floors are 3.5.6-1~deb13u2 for the earlier set and 3.5.7-1~deb13u2 for the later set. The target should therefore be at least 3.5.7-1~deb13u2 for both packages.

Expected outcome

  • Refresh the Unbound runtime/base package set so both OpenSSL packages are at 3.5.7-1~deb13u2 or later.
  • Keep the OpenSSL package versions coherent; do not update only one of libssl3t64 and openssl-provider-fips.
  • Build and exercise the Unbound image, including startup and DNS resolution behavior.
  • Publish a replacement release and verify all 36 OpenSSL occurrences are absent from its vulnerability results.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions