Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:55784

Опубликовано: 18 авг. 2026
Источник: rocky
Оценка: Important

Описание

Important: unbound security update

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-unboundaarch645.14.el8_10python3-unbound-1.16.2-5.14.el8_10.aarch64.rpm
unboundaarch645.14.el8_10unbound-1.16.2-5.14.el8_10.aarch64.rpm
unbound-develaarch645.14.el8_10unbound-devel-1.16.2-5.14.el8_10.aarch64.rpm
unbound-libsaarch645.14.el8_10unbound-libs-1.16.2-5.14.el8_10.aarch64.rpm
python3-unboundx86_645.14.el8_10python3-unbound-1.16.2-5.14.el8_10.x86_64.rpm
unboundx86_645.14.el8_10unbound-1.16.2-5.14.el8_10.x86_64.rpm
unbound-develi6865.14.el8_10unbound-devel-1.16.2-5.14.el8_10.i686.rpm
unbound-develx86_645.14.el8_10unbound-devel-1.16.2-5.14.el8_10.x86_64.rpm
unbound-libsi6865.14.el8_10unbound-libs-1.16.2-5.14.el8_10.i686.rpm
unbound-libsx86_645.14.el8_10unbound-libs-1.16.2-5.14.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 8.6
redhat
2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
nvd
2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
msrc
2 месяца назад

Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

CVSS3: 7.5
debian
2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient v ...