26.7.6: unbound (and syslog-ng) segfault with signal 11 after upgrade (Hyper-V)

Started by Nex VII, October 08, 2026, 08:38:22 PM

Previous topic - Next topic

Great to hear.  We'll pick this up in a small .7 early next week.


Cheers,
Franco

Update from my side: the test kernel (26.7.6-hyperv) is installed on the Hyper-V Gen2 VM (host Xeon E-2236, 4 vCPU, 8 GB).

- Booted 2026-10-09 17:23 CEST, uptime now 2h02m.
- No "exited on signal" entries in System > Log Files > General since boot. With the stock 26.7.6 kernel, unbound was exiting on signal 11 every 6-12 minutes and syslog-ng twice.
- No log entries above Warning since boot; all services running.

Thanks for the quick fix, Franco!


I can confirm a similar problem with OPNsense 26.7.6 on Hyper-V.

My setup is a Windows 11 Hyper-V host with an AMD Ryzen 7 8745HS, and an OPNsense VM with 2 vCPUs and 4 GB RAM. Unbound has DNSSEC and the Python DNS blocklist module enabled.

After updating on 9 October, Unbound repeatedly exited with signal 11. The WAN connection remained up, but DNS requests to the router timed out. Direct internet access by IP still worked.

These are the crash timestamps recorded in the kernel log (BST):

- 09:01:57
- 09:02:03
- 09:39:15
- 09:49:58
- 09:50:15
- 10:40:20
- 10:44:44

The kernel messages were of this form:

    pid 52844 (unbound), jid 0, uid 59: exited on signal 11 (no core dump - denied by kern.coredump)

Restarting Unbound only restored DNS temporarily. Restarting the Windows host also did not stop the crashes; Unbound crashed again after the VM came back up.

I rolled back ONLY the kernel using:

    opnsense-update -kr 26.7.4

The kernel installed successfully, then I rebooted OPNsense. The application and packages remained on 26.7.6. No resolver, blocklist, firewall or VM settings were changed as part of this recovery.

Before rollback:

    FreeBSD 15.1-RELEASE-p4 stable/26.7-n284150-0a7d52ef8757

After rollback:

    FreeBSD 15.1-RELEASE-p3 stable/26.7-n283949-083dc7025377

As of 10 October at 11:27 BST, the VM has been up for approximately 24 hours 34 minutes. Unbound is running, DNS lookups through the router succeed, and HTTPS through the router works. No Unbound signal-11 entries appear in the current system log, although it has rotated, so I cannot claim complete log coverage for the whole period.

One additional point: the normal update offer now includes both opnsense 26.7.6_3 and kernel 26.7.6, which would undo this workaround. I have not installed it.

This seems consistent with the Hyper-V kernel regression discussed here. I have not tested the 26.7.6-hyperv test kernel, and I have no crash backtrace because core dumps were disabled.