New unbound for Debian available [1.10.1]

Bug Fixes:

  • CVE-2020-12662 Unbound can be tricked into amplifying an incoming
    query into a large number of queries directed to a target.
  • CVE-2020-12663 Malformed answers from upstream name servers can be
    used to make Unbound unresponsive.


Thanks mibere and I saw that closed topic. I wanted to share that the package is now available directly for Debian and so no compiling is needed.

This was a really fast release in Debian.

It is only available in Sid though - which is classified as unstable.
Bullseye is in testing (and is the next one after Buster) and has version 1.10.0 within its packages.
Buster (the current release) has version 1.9.0

In a few day it mostly is also available Bullseye. If you sort out the dependencies you can install it also. In my case it running on Jessie which took a lot of work in several updates in time.

Unbound is now also in Bullseye (testing).

The stable version of Unbound in Debian had also it's security patch:

There is now a backport version of Unbound 1.10.1-1 available fur Debian Buster :clapping: and so who is running Debian Buster on their devices can now use the most recent version of Unbound.


And Unbound 1.11.0 is now available.

it would be nice if a version is released in raspberry.

You mean in the Operating System you use?
That is not up to the developers here or to the Unbound developers to decide...
People at Raspberry Pi OS make that call (and are typically quite slow in implementing new versions of Unbound it seems)

It is still based on Debian and it is already known that there is a new version. The maintainer (Edmonds) have to find time to push it to Debian.

Last time it was even back-ported to Buster. :slight_smile:

Unbound was relead for the Debian SID version. It will take a little time to be also backported to Buster:

unbound (1.11.0-1) unstable; urgency=medium

[ Simon Deziel ]

  • systemd: don't create a PID file
  • debian/package-helper: mount --bind systemd notify socket into chroot
    (Closes: #867187)

[ Robert Edmonds ]

  • New upstream version 1.11.0
    • Merge PR #241 by Robert Edmonds: contrib/ Do not use
      "Requires:". (Closes: #958331)
    • Introduce "include-toplevel:" configuration option.
    • Adds its own implementation of Frame Streams for dnstap support.
  • debian/control: Remove build dependency on libfstrm-dev
  • debian/unbound.conf: Use "include-toplevel:" instead of "include:"
    (Closes: #950754)
  • debian/NEWS: Add entry for 1.11.0-1 regarding the change of
    /etc/unbound/unbound.conf to using the "include-toplevel:" directive
  • debian/patches/: Refresh patches

-- Robert Sun, 09 Aug 2020 20:57:15 -0400

And how can I install or update to Unbound 1.11.0 ?

Which version of Debian do you use Buster, Bullseye or SID?

The are released in stages and the next one will be Bullseye and then there will be a back-ported version to Buster.


They implemented now also Bullseye and Buster back-port is accepted to test.

Have look here to see the current status:

And Unbound 1.11.1 has been backported to Buster and so available to all Raspberry that are on Debian 10 (Buster).

fingers cross its not too long before they move it to the Stable release.

As already stated it is backported to stable/Buster/10 and I think this will make it available:

sudo deb buster-backports main 
sudo apt update
sudo apt install unbound

I am still on Jessie/8 so I can't test it.

Unbound 1.12.0-1 is now available for Buster (Debian 10) as back port and the release notes can be found here:

On the Debian site: