[CLSA-2026:1785489388] unbound: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 09:16:43 UTC
Description:
- CVE-2026-50243: do not let response-ip/rpz rewrite a BOGUS answer; return SERVFAIL - CVE-2026-42923: cap NSEC3 hash calculations in the negative-cache DS proof and reject oversized NSEC3 salt - CVE-2024-43168: reject negative port numbers in outgoing-port-permit/avoid to prevent an out-of-bounds write
Updated packages:
  • python3-unbound-1.16.2-5.el8.tuxcare.els10.x86_64.rpm
    sha:93cedd8ec68e382bb85072a26b652e0fed0274102d02e65dfa274982a294c25f
  • unbound-1.16.2-5.el8.tuxcare.els10.x86_64.rpm
    sha:514fe4e5014076809c6d6a4e8d7462a85a3611d57d21347e5683a5816122affa
  • unbound-devel-1.16.2-5.el8.tuxcare.els10.i686.rpm
    sha:e57a026ce6bac67baab6a29c0dd53df7da04af0fe3853f7cc3e001107aff0f34
  • unbound-devel-1.16.2-5.el8.tuxcare.els10.x86_64.rpm
    sha:012306ce07893e4c5baedd0dbb967c0cb0b2db03ab66e57af89b4c2496ae824b
  • unbound-libs-1.16.2-5.el8.tuxcare.els10.i686.rpm
    sha:5c8e7b6c115f1f75c29bca1bfa3fe9684c2923435dd8061ea2a96365d822793f
  • unbound-libs-1.16.2-5.el8.tuxcare.els10.x86_64.rpm
    sha:12c8ec9a46493f0ba8242942b01a09ca523a4eeafb131e8793c50f8008edc40f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.