Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:18931

Опубликовано: 28 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: unbound security update

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: DNSBomb vulnerability (CVE-2024-33655)

  • unbound: Unbound domain hijacking via promiscuous records (CVE-2025-11411)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
python3-unboundx86_642.el9python3-unbound-1.24.2-2.el9.x86_64.rpm
unboundx86_642.el9unbound-1.24.2-2.el9.x86_64.rpm
unbound-dracutx86_642.el9unbound-dracut-1.24.2-2.el9.x86_64.rpm
unbound-libsi6862.el9unbound-libs-1.24.2-2.el9.i686.rpm
unbound-libsx86_642.el9unbound-libs-1.24.2-2.el9.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
2 месяца назад

Moderate: unbound security update

oracle-oval
около 2 месяцев назад

ELSA-2026-18931: unbound security update (MODERATE)

CVSS3: 7.5
ubuntu
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 3.7
redhat
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
nvd
около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.