Release date:
2026-08-21 13:02:14 UTC
Description:
- CVE-2024-33655: add the upstream wait-limit and discard-timeout mechanism
so accumulated recursion replies can no longer be released as a pulsing
burst (DNSBomb), including every upstream follow-up to that mechanism:
discard only UDP replies and never a reply on an open stream connection,
clear the HTTP/2 stream back-pointer on the drop paths, account discarded
replies in mesh num_reply_addrs, and fix CVE-2026-56444 in the
serve-expired discard path
- CVE-2024-43167: NULL-check the first forward stub name in ub_ctx_set_fwd()
to prevent a NULL pointer dereference in libunbound, and reject a
forward-zone, stub-zone or view without a name at config parse time so no
name-less object reaches the daemon
- CVE-2026-42955: clamp the cached TTL of parent-side A/AAAA glue as well as
NS records so a client query can no longer renew a ghost domain delegation
- CVE-2026-46582: keep a secure wildcard RRset out of the rrset cache until
the NSEC wildcard proof completes, preventing poisoning via the
serve-expired reply path
- CVE-2026-50243: skip the response-ip/RPZ rewrite for BOGUS answers so a
spoofed DNSSEC-protected answer is no longer redirected as INSECURE
- CVE-2026-55708: enter the default-protected local zones when
unbound-control view_local_data creates a view-specific local zone tree
Updated packages:
-
python3-unbound-1.16.2-3.el9_2.tuxcare.els14.x86_64.rpm
sha:d3bde341bc1187d2d708974af41553e4cd3e40f8b0422289c581de7dae0ba9f0
-
unbound-1.16.2-3.el9_2.tuxcare.els14.x86_64.rpm
sha:0322fc6d1e5b80f1b28a119e443639215b16164e8bd1959751704cf190e0ed8a
-
unbound-devel-1.16.2-3.el9_2.tuxcare.els14.i686.rpm
sha:f9160b9d3be44825fdcdbde6d1696d157b32235d38e917fbe7a16cae8a399b16
-
unbound-devel-1.16.2-3.el9_2.tuxcare.els14.x86_64.rpm
sha:00f9db6aa536ac8adc70eac421afbe6ce7e58523cfd473d05aa90d3d87f68a43
-
unbound-libs-1.16.2-3.el9_2.tuxcare.els14.i686.rpm
sha:2868a05fbb4eee4d1e5296eb1d3ceedad35d51b61b3466cb66fdb777e32823a0
-
unbound-libs-1.16.2-3.el9_2.tuxcare.els14.x86_64.rpm
sha:acb5ac09f0810fa6711e4c1742b454ae675deff5c163a93eeb5dc3e50eeebb5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.