[CLSA-2026:1779535502] unbound: Fix of CVE-2026-33278
Type:
security
Severity:
Critical
Release date:
2026-05-23 11:25:06 UTC
Description:
- CVE-2026-33278: possible remote code execution during DNSSEC validation via a dangling rrsets pointer in dns_msg_deepcopy_region exposed by the backported KeyTrap mitigation
Updated packages:
  • python3-unbound-1.16.2-19.el9_6.1.tuxcare.els1.x86_64.rpm
    sha:bff983cfa67f1b0b33e224e732cf0f64fe792b0b23866ee8c8e397226df38c4d
  • unbound-1.16.2-19.el9_6.1.tuxcare.els1.x86_64.rpm
    sha:9738bfdc3d508a9fdd749f484117dab1b50f584898172c60ab83a4a46c9a1a28
  • unbound-devel-1.16.2-19.el9_6.1.tuxcare.els1.i686.rpm
    sha:81a1de0cb4ebded2c8329d3283818148becbd6577b7178c07f7322cfd8ae123b
  • unbound-devel-1.16.2-19.el9_6.1.tuxcare.els1.x86_64.rpm
    sha:71995973495112a79b00992000b1fcdb2067f3480d1b3eae5c48c07cc6871239
  • unbound-dracut-1.16.2-19.el9_6.1.tuxcare.els1.x86_64.rpm
    sha:8969f4ee4d6f77d41ef9c286091fd4ffda762edbb45442c935db5ebe1d19f913
  • unbound-libs-1.16.2-19.el9_6.1.tuxcare.els1.i686.rpm
    sha:d3f1db6c82e19cb9729794a40b3da4edcfe4ea381882af53125aa2cd1d86de0b
  • unbound-libs-1.16.2-19.el9_6.1.tuxcare.els1.x86_64.rpm
    sha:0e5c54156bf211e229a108bda542c63f0645739b6185fca99e9140d5bf4d8e14
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.