[CLSA-2026:1791333832] unbound: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-10-08 22:25:10 UTC
Description:
- CVE-2026-81642: fix heap buffer overflow when digesting DNSKEY - CVE-2026-81634: add the missing first owner name and signature length bounds checks to rrset_canonical(), preventing a heap buffer overflow during RRset canonicalisation - CVE-2026-82717: restore the packet buffer position on malformed names in pkt_dname_len() and bound the copy lengths in rdata_copy(), preventing heap corruption on the CNAME synthesis error path - CVE-2026-85501: bound DNSSEC validation work per query: key-tag matches capped at 256, NSEC/NSEC3 verifications at 8 per message, new val-validation-attempts and val-hash-attempts options (default 32), oversized referral DS RRsets shortened to 20, and val-clean-additional now defaults to no
Updated packages:
  • unbound-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
    sha:af2e5ecdb1c4b846431d7aa3ae0f297f2eabbda3746821fbb190109b7931198b
  • unbound-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
    sha:26b232046d7467193f40920979b29501fa347f1db9deac4c08a950ce85042177
  • unbound-devel-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
    sha:161aed9ad73c815ae58bf8adbe59ab55d771bd10f52598745006f998617d0527
  • unbound-devel-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
    sha:feb423531f6d3a98df808e7148417cfbc263c09ca0724e4f995ede468c0c09d5
  • unbound-libs-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
    sha:837f63ad1d4a8049c37aa3e304860a5f80ed17b30844326af56c449725586794
  • unbound-libs-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
    sha:23e5df65253b67ed3e5855acfcd0ccd29234674aa1e91fcb10e706f0fa20e165
  • unbound-python-1.6.6-5.0.1.el7_8.tuxcare.els2.i686.rpm
    sha:3645feb9ef0658281569fb6a6c8033084cb79546df4a5e302eb33bdfb0296574
  • unbound-python-1.6.6-5.0.1.el7_8.tuxcare.els2.x86_64.rpm
    sha:d3e8e8f63af5e2fd728dc832da461933851ae51c8df83fbfe32727723c365679
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.