[CLSA-2026:1790264021] unbound: Fix of CVE-2026-81642
Type:
security
Severity:
Critical
Release date:
2026-09-24 15:33:51 UTC
Description:
- CVE-2026-81642: check the scratch buffer capacity in ds_create_dnskey_digest() before writing the DNSKEY owner name and RDATA into it, so a DNSKEY whose owner name plus RDATA exceeds the buffer can no longer overflow it
CVEs fixed:
Updated packages:
  • python3-unbound-1.16.2-5.el8.tuxcare.els11.i686.rpm
    sha:74e0a49113ef52356ae38c53e4716eb201478c816bb39d58da65a061001bec87
  • python3-unbound-1.16.2-5.el8.tuxcare.els11.x86_64.rpm
    sha:620d11e3ae16cb2389cc49b18f9cd688547ae9f2db13c7f5a0a4a3c4cd1ff034
  • unbound-1.16.2-5.el8.tuxcare.els11.i686.rpm
    sha:c745594beefddb9f2e72d56da8165d807daee96f9b5458ed3e1cad4726cf0a47
  • unbound-1.16.2-5.el8.tuxcare.els11.x86_64.rpm
    sha:f1fe1ef853d2533f525d970889ad126f3b40e0e6f4e082a3397dc09be20bfc7c
  • unbound-devel-1.16.2-5.el8.tuxcare.els11.i686.rpm
    sha:7080af124a94edd628361dc5d97d5ef0b29777a522d6a27a0ddc80138e596bb5
  • unbound-devel-1.16.2-5.el8.tuxcare.els11.x86_64.rpm
    sha:5a6b99d989a52aec2068ee4bb4511e545a246fb8370ad1392f9e9450c7080273
  • unbound-libs-1.16.2-5.el8.tuxcare.els11.i686.rpm
    sha:0efa16d477a763ef6fbba8e90e05b3145da92e51f3cdba273eca9c50000da209
  • unbound-libs-1.16.2-5.el8.tuxcare.els11.x86_64.rpm
    sha:93ec1ca2318e9137354ce84e0f16dcbfcaccc658a4f3863ca14cab9d933945fd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.