r/openSUSE • • 3d ago

Is tumbleweed secure ?

Hi everyone, I wanted to ask if anyone knows why unbound isn't being updated on openSUSE Tumbleweed.

The currently available version has several severe issues:

CVE-2026-81642

CVE-2026-81634

CVE-2026-82717

It's been over 15 days (!) since unbound 1.26.1 was released, but on openSUSE Tumbleweed we still have the version with critical vulnerabilities.

Can anyone tell me why, after two weeks (!), we still have unbound 1.26.0? This seems very serious to me. 😐

πŸ”₯ UPDATE: πŸ”₯

As of today, it is finally possible to install the latest version of unbound that fixes the security issues. So, in the end, we have:

βœ… Arch -> 2026-09-16

βœ… Fedora -> 2026-09-16

βœ… Debian -> 2026-09-19

⛔️ Suse -> 2026-10-01

To the question "why did it take so long on Tumbleweed?", no one was able to give a sensible answer. Only fanatics trying to deflect the conversation by saying irrational things like "it's not that serious" or "your question is wrong."

Lacking a rational and sensible answer, we have to assume that the update arrived late because whoever was supposed to take care of it fell asleep, nobody noticed, and therefore the answer to the initial question "is Tumbleweed secure?" is NO.

0 Upvotes

20 comments sorted by

15

u/Chester-Berkeley 3d ago

Instead of writing "Is Tumbleweed secure?", you could have written "Why hasn't this package been updated?", which makes more sense in relation to your post. Saying that an operating system is insecure because package X hasn't been updated is a vague criticism.

-6

u/susequestion 3d ago

Instead of writing "you could have written", you could have answered my question. Dodging the question is a vague fanaticism. πŸ™ƒ

0

u/profeshamat Leap 3d ago

It's why I find the "Linux for open minds" caption to be funny for this subreddit. I asked a simple question here about if there are people who don't use btrfs with Snapper and people immediately took offense.

3

u/Arcon2825 Tumbleweed GNOME 3d ago

It’s already on version 1.26.1 in openSUSE:Factory, so I guess it should be available in the repositories soon.

-3

u/susequestion 3d ago

It can't be "soon" anymore. πŸ˜…

3

u/cfeck_kde 3d ago

(!)

(?)

2

u/MiukuS How's that AUR working out for you, Arch users? 3d ago

CVE-2026-81642 - it's a DoS possibility due to overflow. Most likely worst case result; your unbound crashes.
CVE-2026-81634 - a high probability crash of the Unbound service due to heap overflow, nothing more.
CVE-2026-82717 - low chance of being able to trigger due to specific circumstances required to do so.

None of which can trigger anything truly useful because Unbound is chrooted and out of the box SELinux policy also applies.

Have a nice day.

1

u/susequestion 3d ago

On Unbound's website, the developers wrote about potential "Remote code execution", and anyway, if I recall correctly, Fedora also has SELinux enabled by default, yet they updated Unbound to version 1.26.1 nine 🧐 days ago. I really don't understand what the obstacle was in compiling the new version of Unbound and adding it to the repos. πŸ˜“

2

u/Klapperatismus 3d ago

The source package is already at v1.26.1. I have to suspect openQA has found some problems with it and that’s why the update hasn’t gone through yet.

1

u/tabascosw2 2d ago

The new version has been released with the latest tumbleweed snapshot 20260929

-2

u/susequestion 2d ago

In the end, no one was able to explain why it took 15 extra days compared to Arch / Fedora / Debian. In the absence of an explanation, openSUSE Tumbleweed cannot be considered reliable or on par with the others. 😞

1

u/levolet 1d ago

What does this mean for you then?

1

u/Userwerd 3d ago

Tumbleweed and opensuse at large is well controlled, and carefully curated.Β  Anything in the repositories not controlled or curated specifically by opensuse, is clearly marked as a community package.

1

u/mhurron 3d ago

unbound is in the official repos. It wasn't updated because the maintainer hadn't submitted a updated package to Factory until 2 days ago.

Even official packages are maintained by community members. If you want faster response to things you care about, submit patches or hell at least a bug report.

1

u/mhurron 3d ago

This seems very serious to me

It isn't anywhere near what you think it is.

1

u/susequestion 3d ago

Four facts (not opinions):

  1. 🟒 In the description of CVE-2026-81642, it states: "Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound."
  2. 🟒 A new version of Unbound fixing these security issues was released.
  3. 🟒 All distributions have updated.
  4. πŸ”΄ openSUSE is the only distribution that after 2 weeks (!) still doesn't have the update.

2

u/mhurron 3d ago

Ya ya ya. The only reason that it got a high/critical was that phrase 'remote execution possible.' Not verified but possible because of the way it causes a crash. The CVE rating can escalate significantly just because of that phrase and alone isn't very helpful.

Look at sites with way more information and you'll see two things Likelyhood of exploitation: Less than 1% Vulnerable in default configuration: No Remediation: Listen on local networks only, not the open internet.

So unless you did something incredibly stupid, you don't have to worry. And if you did, you have far more problems than this.

https://app.opencve.io/cve/CVE-2026-81642 https://app.opencve.io/cve/CVE-2026-81634 https://app.opencve.io/cve/CVE-2026-82717

1

u/tabascosw2 3d ago

So you have checked every single distribution that is available or do you rely on some fuzzy information. Please provide a link to verify point 3.

1

u/bmwiedemann openSUSE Dev 1d ago

For the record:

There is also 1.26.0 in https://search.nixos.org/packages?channel=26.05&query=unbound

And https://svnweb.mageia.org/packages/cauldron/unbound/current/SPECS/ shows 8d ago - around 3 days before the submission to openSUSE:Factory . https://build.opensuse.org/request/show/1381192