unbound-1.16.2-5.14.el8_10
エラータID: AXSA:2026-1573:10
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-44690
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.
Update packages.
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.
N/A
SRPMS
- unbound-1.16.2-5.14.el8_10.src.rpm
MD5: 5cf3e5fb3d7814b10bac509dcbc822ae
SHA-256: a93c908a63da82db086c1d20b76aa76351745aeaefc4cdb7a053b05a9e4d4b8f
Size: 6.04 MB
Asianux Server 8 for x86_64
- python3-unbound-1.16.2-5.14.el8_10.x86_64.rpm
MD5: 6d6ef48bfa1450658508a9ed1536f212
SHA-256: 8daeb01a36ad6d704a78c0e05c60ae7da80ea146ddcf75c7c159e3e483f5ca02
Size: 129.90 kB - unbound-1.16.2-5.14.el8_10.x86_64.rpm
MD5: 4617adb1b366df75527e467edeec0420
SHA-256: 00eebe9b5f39d20007da925cfd0e3b550009ae596268551d8e51cb8c1f1083df
Size: 1.00 MB - unbound-devel-1.16.2-5.14.el8_10.i686.rpm
MD5: d9fba177fd624495dd1d1dfe9944b4f6
SHA-256: 505a15cbff039ccae0b97658d86707d1fc78098a4fdbffbf9c7d4bdfbdf7002c
Size: 57.31 kB - unbound-devel-1.16.2-5.14.el8_10.x86_64.rpm
MD5: 3912fdb3697543259a26b6944e6031fb
SHA-256: 2b0bcfe32af3ff5e61e86a5d5b9fb6b5e725b2cdbcc0221752763205f667abdc
Size: 57.30 kB - unbound-libs-1.16.2-5.14.el8_10.i686.rpm
MD5: 40f102d1fbd745cadfa2a90609910ef8
SHA-256: 3d2b016a5f0932730f3520bf6551ab9ef43ede84943dc7b5132bc7c2fb8db66a
Size: 618.88 kB - unbound-libs-1.16.2-5.14.el8_10.x86_64.rpm
MD5: e03b09f5854a5ffa4921497709759ae8
SHA-256: c67dd71d1797ca982308d31fdbed4b40593cf6bf218942c4b7b0c142fa86a92c
Size: 578.23 kB