Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18556

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: unbound security update

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: DNSBomb vulnerability (CVE-2024-33655)

  • unbound: Unbound domain hijacking via promiscuous records (CVE-2025-11411)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
unboundaarch647.el10unbound-1.24.2-7.el10.aarch64.rpm
python3-unboundaarch647.el10python3-unbound-1.24.2-7.el10.aarch64.rpm
unbound-libsaarch647.el10unbound-libs-1.24.2-7.el10.aarch64.rpm
unbound-anchoraarch647.el10unbound-anchor-1.24.2-7.el10.aarch64.rpm
unbound-dracutaarch647.el10unbound-dracut-1.24.2-7.el10.aarch64.rpm
unbound-utilsaarch647.el10unbound-utils-1.24.2-7.el10.aarch64.rpm
unbound-dracutx86_647.el10unbound-dracut-1.24.2-7.el10.x86_64.rpm
unbound-utilsx86_647.el10unbound-utils-1.24.2-7.el10.x86_64.rpm
unboundx86_647.el10unbound-1.24.2-7.el10.x86_64.rpm
unbound-anchorx86_647.el10unbound-anchor-1.24.2-7.el10.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
2 месяца назад

Moderate: unbound security update

oracle-oval
около 2 месяцев назад

ELSA-2026-18931: unbound security update (MODERATE)

oracle-oval
25 дней назад

ELSA-2026-18556: unbound security update (MODERATE)

CVSS3: 7.5
ubuntu
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 3.7
redhat
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.