Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:23231

Опубликовано: 06 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: unbound security update

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: Heap overflow and crash with multiple nsid, cookie, padding EDNS options (CVE-2026-42944)

  • unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages (CVE-2026-42959)

  • unbound: Unbound DNSSEC Validator Use-After-Free via Deep Copy Pointer Overwrite Leading to DoS and Possible Remote Code Execution (CVE-2026-33278)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
unbound-anchorx86_647.el10_2.1unbound-anchor-1.24.2-7.el10_2.1.x86_64.rpm
unbound-dracutx86_647.el10_2.1unbound-dracut-1.24.2-7.el10_2.1.x86_64.rpm
unboundx86_647.el10_2.1unbound-1.24.2-7.el10_2.1.x86_64.rpm
python3-unboundx86_647.el10_2.1python3-unbound-1.24.2-7.el10_2.1.x86_64.rpm
unbound-utilsx86_647.el10_2.1unbound-utils-1.24.2-7.el10_2.1.x86_64.rpm
unbound-libsx86_647.el10_2.1unbound-libs-1.24.2-7.el10_2.1.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
около 2 месяцев назад

Important: unbound security update

oracle-oval
около 1 месяца назад

ELSA-2026-24369: unbound security update (IMPORTANT)

suse-cvrf
около 1 месяца назад

Security update for unbound

suse-cvrf
около 2 месяцев назад

Security update for unbound

suse-cvrf
около 2 месяцев назад

Security update for unbound