Release date:
2026-10-08 22:25:10 UTC
Description:
- CVE-2026-81642: fix heap buffer overflow when digesting DNSKEY
- CVE-2026-81634: add the missing first owner name and signature length
bounds checks to rrset_canonical(), preventing a heap buffer overflow
during RRset canonicalisation
- CVE-2026-82717: restore the packet buffer position on malformed names
in pkt_dname_len() and bound the copy lengths in rdata_copy(),
preventing heap corruption on the CNAME synthesis error path
- CVE-2026-85501: bound DNSSEC validation work per query: key-tag
matches capped at 256, NSEC/NSEC3 verifications at 8 per message, new
val-validation-attempts and val-hash-attempts options (default 32),
oversized referral DS RRsets shortened to 20, and val-clean-additional
now defaults to no
Updated packages:
-
unbound-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
sha:af2e5ecdb1c4b846431d7aa3ae0f297f2eabbda3746821fbb190109b7931198b
-
unbound-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
sha:26b232046d7467193f40920979b29501fa347f1db9deac4c08a950ce85042177
-
unbound-devel-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
sha:161aed9ad73c815ae58bf8adbe59ab55d771bd10f52598745006f998617d0527
-
unbound-devel-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
sha:feb423531f6d3a98df808e7148417cfbc263c09ca0724e4f995ede468c0c09d5
-
unbound-libs-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
sha:837f63ad1d4a8049c37aa3e304860a5f80ed17b30844326af56c449725586794
-
unbound-libs-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
sha:23e5df65253b67ed3e5855acfcd0ccd29234674aa1e91fcb10e706f0fa20e165
-
unbound-python-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
sha:3645feb9ef0658281569fb6a6c8033084cb79546df4a5e302eb33bdfb0296574
-
unbound-python-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
sha:d3e8e8f63af5e2fd728dc832da461933851ae51c8df83fbfe32727723c365679
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.