[CLSA-2026:1785417704] unbound: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-30 13:21:57 UTC
Description:
- CVE-2026-50243: do not let response-ip/rpz rewrite a BOGUS answer; return SERVFAIL - CVE-2026-42923: cap NSEC3 hash calculations in the negative-cache DS proof and reject oversized NSEC3 salt - CVE-2024-43168: reject negative port numbers in outgoing-port-permit/avoid to prevent an out-of-bounds write
Updated packages:
  • python3-unbound-1.16.2-19.el9_6.1.tuxcare.els10.x86_64.rpm
    sha:3641eccf5a616266a8a9c19717e839d5f4cd8f73e34f74b1dce0f3ee8ed71f3c
  • unbound-1.16.2-19.el9_6.1.tuxcare.els10.x86_64.rpm
    sha:6aa33dd36310cffa95779b44932b446ba9d21ec20464c4dba37c12096c7f59aa
  • unbound-devel-1.16.2-19.el9_6.1.tuxcare.els10.i686.rpm
    sha:74cd1e9f4d93747bdac6426d9888a50eef4c2eb7580e13e1f7b5f0b71ccf9536
  • unbound-devel-1.16.2-19.el9_6.1.tuxcare.els10.x86_64.rpm
    sha:5871821b9217a4cce95127cffba080728af464a7b27331fc6876c07c9ce8cfea
  • unbound-dracut-1.16.2-19.el9_6.1.tuxcare.els10.x86_64.rpm
    sha:3d879331d497b0e522f1beca15474f2a750c6eabb1a5c5aa3d1f73730bae1440
  • unbound-libs-1.16.2-19.el9_6.1.tuxcare.els10.i686.rpm
    sha:5a87be5a849c2f8f9271dba540f23b60df662c5bb7efb296ab52ec047c45f758
  • unbound-libs-1.16.2-19.el9_6.1.tuxcare.els10.x86_64.rpm
    sha:20d3b55d4e6ddd579e51a9c6c2ae5b22f7a2cc74a987de83318dc0e7e8ea4fda
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.