Update unbound-anchor built-in dnssec key

Key was updated in config files, but not properly in unbound-anchor too.
That should contain new key as well.

Resolves: RHEL-131172
(cherry picked from commit 03575da4cc85a14edb99a0f640bfe2787682ab2a)
This commit is contained in:
Petr Menšík 2026-04-16 17:35:22 +02:00
parent f8a9246aa4
commit dd460a1e9c
2 changed files with 33 additions and 0 deletions

View File

@ -0,0 +1,29 @@
From acc84268e4156fb9a8dd36eafaf04d064ee5895a Mon Sep 17 00:00:00 2001
From: "W.C.A. Wijngaards" <wouter@nlnetlabs.nl>
Date: Thu, 25 Jul 2024 11:42:22 +0200
Subject: [PATCH] - Add root key 38696 from 2024 for DNSSEC validation. It is
added to the default root keys in unbound-anchor. The content can be
inspected with `unbound-anchor -l`.
---
unbound-1.20.0/smallapp/unbound-anchor.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/unbound-1.20.0/smallapp/unbound-anchor.c b/unbound-1.20.0/smallapp/unbound-anchor.c
index 137b2e9..8738cf2 100644
--- a/unbound-1.20.0/smallapp/unbound-anchor.c
+++ b/unbound-1.20.0/smallapp/unbound-anchor.c
@@ -183,7 +183,9 @@ static const char DS_TRUST_ANCHOR[] =
/* The anchors must start on a new line with ". IN DS and end with \n"[;]
* because the makedist script greps on the source here */
/* anchor 20326 is from 2017 */
-". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D\n";
+". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D\n"
+ /* anchor 38696 is from 2024 */
+". IN DS 38696 8 2 683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16\n";
/** verbosity for this application */
static int verb = 0;
--
2.53.0

View File

@ -76,6 +76,8 @@ Patch5: unbound-1.21-CVE-2024-8508.patch
# https://github.com/NLnetLabs/unbound/commit/5bf82f246481098a6473f296b21fc1229d276c0f
# https://github.com/NLnetLabs/unbound/commit/a1150078f29e14b36c8e4d9d05a263a5e6abbc5b
Patch6: unbound-1.23.1-CVE-2025-5994.patch
# https://github.com/NLnetLabs/unbound/commit/f094f4ea3c943c5b5b2b6fa8bee0e7a8f3cfdc51
Patch7: unbound-1.20-unbound-anchor-key-38696.patch
BuildRequires: gdb
BuildRequires: gcc, make
@ -181,6 +183,7 @@ pushd %{pkgname}
%patch4 -p2 -b .CVE-2023-50387-CVE-2023-50868
%patch5 -p2 -b .CVE-2024-8508
%patch6 -p2 -b .CVE-2025-5994
%patch7 -p2 -b .dnssec-ta-2024
# copy common doc files - after here, since it may be patched
@ -450,6 +453,7 @@ popd
%changelog
* Tue Nov 11 2025 Petr Menšík <pemensik@redhat.com> - 1.16.2-5.10
- Add new root key 38696 (RHEL-131172)
- Update unbound-anchor built-in dnssec key
* Thu Jul 24 2025 Tomas Korbar <tkorbar@redhat.com> - 1.16.2-5.9
- Fix RebirthDay Attack (CVE-2025-5994)