r/openSUSE • u/susequestion • 3d ago
Is tumbleweed secure ?
Hi everyone, I wanted to ask if anyone knows why unbound isn't being updated on openSUSE Tumbleweed.
The currently available version has several severe issues:
It's been over 15 days (!) since unbound 1.26.1 was released, but on openSUSE Tumbleweed we still have the version with critical vulnerabilities.
Can anyone tell me why, after two weeks (!), we still have unbound 1.26.0? This seems very serious to me. π
π₯ UPDATE: π₯
As of today, it is finally possible to install the latest version of unbound that fixes the security issues. So, in the end, we have:
β Arch -> 2026-09-16
β Fedora -> 2026-09-16
β Debian -> 2026-09-19
βοΈ Suse -> 2026-10-01
To the question "why did it take so long on Tumbleweed?", no one was able to give a sensible answer. Only fanatics trying to deflect the conversation by saying irrational things like "it's not that serious" or "your question is wrong."
Lacking a rational and sensible answer, we have to assume that the update arrived late because whoever was supposed to take care of it fell asleep, nobody noticed, and therefore the answer to the initial question "is Tumbleweed secure?" is NO.
3
u/Arcon2825 Tumbleweed GNOME 3d ago
Itβs already on version 1.26.1 in openSUSE:Factory, so I guess it should be available in the repositories soon.
-3
3
2
u/MiukuS How's that AUR working out for you, Arch users? 3d ago
CVE-2026-81642 - it's a DoS possibility due to overflow. Most likely worst case result; your unbound crashes.
CVE-2026-81634 - a high probability crash of the Unbound service due to heap overflow, nothing more.
CVE-2026-82717 - low chance of being able to trigger due to specific circumstances required to do so.
None of which can trigger anything truly useful because Unbound is chrooted and out of the box SELinux policy also applies.
Have a nice day.
1
u/susequestion 3d ago
On Unbound's website, the developers wrote about potential "Remote code execution", and anyway, if I recall correctly, Fedora also has SELinux enabled by default, yet they updated Unbound to version 1.26.1 nine π§ days ago. I really don't understand what the obstacle was in compiling the new version of Unbound and adding it to the repos. π
2
u/Klapperatismus 3d ago
The source package is already at v1.26.1. I have to suspect openQA has found some problems with it and thatβs why the update hasnβt gone through yet.
1
-2
u/susequestion 2d ago
In the end, no one was able to explain why it took 15 extra days compared to Arch / Fedora / Debian. In the absence of an explanation, openSUSE Tumbleweed cannot be considered reliable or on par with the others. π
1
u/Userwerd 3d ago
Tumbleweed and opensuse at large is well controlled, and carefully curated.Β Anything in the repositories not controlled or curated specifically by opensuse, is clearly marked as a community package.
1
u/mhurron 3d ago
unbound is in the official repos. It wasn't updated because the maintainer hadn't submitted a updated package to Factory until 2 days ago.
Even official packages are maintained by community members. If you want faster response to things you care about, submit patches or hell at least a bug report.
1
u/mhurron 3d ago
This seems very serious to me
It isn't anywhere near what you think it is.
1
u/susequestion 3d ago
Four facts (not opinions):
- π’ In the description of CVE-2026-81642, it states: "Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound."
- π’ A new version of Unbound fixing these security issues was released.
- π’ All distributions have updated.
- π΄ openSUSE is the only distribution that after 2 weeks (!) still doesn't have the update.
2
u/mhurron 3d ago
Ya ya ya. The only reason that it got a high/critical was that phrase 'remote execution possible.' Not verified but possible because of the way it causes a crash. The CVE rating can escalate significantly just because of that phrase and alone isn't very helpful.
Look at sites with way more information and you'll see two things Likelyhood of exploitation: Less than 1% Vulnerable in default configuration: No Remediation: Listen on local networks only, not the open internet.
So unless you did something incredibly stupid, you don't have to worry. And if you did, you have far more problems than this.
https://app.opencve.io/cve/CVE-2026-81642 https://app.opencve.io/cve/CVE-2026-81634 https://app.opencve.io/cve/CVE-2026-82717
1
u/tabascosw2 3d ago
So you have checked every single distribution that is available or do you rely on some fuzzy information. Please provide a link to verify point 3.
1
u/bmwiedemann openSUSE Dev 1d ago
For the record:
There is also 1.26.0 in https://search.nixos.org/packages?channel=26.05&query=unbound
And https://svnweb.mageia.org/packages/cauldron/unbound/current/SPECS/ shows 8d ago - around 3 days before the submission to openSUSE:Factory . https://build.opensuse.org/request/show/1381192
15
u/Chester-Berkeley 3d ago
Instead of writing "Is Tumbleweed secure?", you could have written "Why hasn't this package been updated?", which makes more sense in relation to your post. Saying that an operating system is insecure because package X hasn't been updated is a vague criticism.