Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18556

Опубликовано: 08 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-18556: unbound security update (MODERATE)

[1.24.2-7]

  • Recreate configure unconditionally

[1.24.2-6]

  • Add byacc into BuildRequires

[1.24.2-5]

  • Change the default of tls-use-system-policy-versions at build-time

[1.24.2-4]

  • Switch TLS configuration to follow TLS sockets by crypto-policy again

[1.24.2-3]

  • Export utils subpackage into AppStream repository

[1.24.2-2]

  • Add Yorgos PGP key for validation

[1.24.2-1]

  • Update to 1.24.2
  • Fixes CVE-2025-11411

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

python3-unbound

1.24.2-7.el10

unbound

1.24.2-7.el10

unbound-anchor

1.24.2-7.el10

unbound-dracut

1.24.2-7.el10

unbound-libs

1.24.2-7.el10

unbound-utils

1.24.2-7.el10

unbound-devel

1.24.2-7.el10

Oracle Linux x86_64

python3-unbound

1.24.2-7.el10

unbound

1.24.2-7.el10

unbound-anchor

1.24.2-7.el10

unbound-dracut

1.24.2-7.el10

unbound-libs

1.24.2-7.el10

unbound-utils

1.24.2-7.el10

unbound-devel

1.24.2-7.el10

Связанные CVE

Связанные уязвимости

rocky
2 месяца назад

Moderate: unbound security update

rocky
2 месяца назад

Moderate: unbound security update

oracle-oval
около 2 месяцев назад

ELSA-2026-18931: unbound security update (MODERATE)

CVSS3: 7.5
ubuntu
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 3.7
redhat
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.