unbound-1.16.2-19.el9_6.1

エラータID: AXSA:2025-10641:06

Release date: 
Tuesday, July 29, 2025 - 22:22
Subject: 
unbound-1.16.2-19.el9_6.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound Cache poisoning (CVE-2025-5994)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-5994
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. unbound-1.16.2-19.el9_6.1.src.rpm
    MD5: c368979ec7aacfacdd364a77ccb17dcb
    SHA-256: 4c12d146fd0cf374cfe8b67503f2d9e390b4bd1e3a412f8567addc33e2cc6ddf
    Size: 6.01 MB

Asianux Server 9 for x86_64
  1. python3-unbound-1.16.2-19.el9_6.1.x86_64.rpm
    MD5: e5ff7aaad166e0984212e2ae34789c74
    SHA-256: c0dc94566ad781a7472d02df9981037c305ee5c47d15e01767f6807c80f774ac
    Size: 105.52 kB
  2. unbound-1.16.2-19.el9_6.1.x86_64.rpm
    MD5: c03c8bc05833c2edf40bdec5bdab1958
    SHA-256: 6df5e678f480d9d1261479cdbd5f86884ce5a9650fb99c3c3f403cc54cf5bda7
    Size: 974.60 kB
  3. unbound-devel-1.16.2-19.el9_6.1.i686.rpm
    MD5: 1bc0f799f969bd559ac0ce593b8eb903
    SHA-256: 55a5f83adac2543d1db258f00068449c52a3b7d7d3dde9ad3d468a342e840e2b
    Size: 38.61 kB
  4. unbound-devel-1.16.2-19.el9_6.1.x86_64.rpm
    MD5: a7393e6c4064fcb6da6f9d2b1dc1e8b8
    SHA-256: 2d65b683cec242b901e860a22c74bbbf57f7f98bab710566f04afaf786e8900b
    Size: 38.59 kB
  5. unbound-dracut-1.16.2-19.el9_6.1.x86_64.rpm
    MD5: 6d9b526d8a8196a27f1f9d788397b851
    SHA-256: 1dc21299feb91a8b4a2ccef5d70a932150e9765adc6b2149129c3888784a73a5
    Size: 9.75 kB
  6. unbound-libs-1.16.2-19.el9_6.1.i686.rpm
    MD5: 242d47e9f300f1e62c7bfa31707eb56c
    SHA-256: 6dc86f606532debc96f0d0fb4cd47884238693ed1b970f3aa44987e48c4f0185
    Size: 575.75 kB
  7. unbound-libs-1.16.2-19.el9_6.1.x86_64.rpm
    MD5: fdf7ed02a4911e82b1e40911dab40ab1
    SHA-256: ccd0ca857d6210ef3cf7c1a3bb17040867b409d997b83c79e7fb86516d8fec0a
    Size: 549.89 kB