unbound-1.24.2-3.el9_8.4
エラータID: AXSA:2026-1692:11
Release date:
Sunday, August 30, 2026 - 14:44
Subject:
unbound-1.24.2-3.el9_8.4
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC
resolver.
Security Fix(es):
unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation
and premature cache writes (CVE-2026-44690)
unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option
(CVE-2026-55973)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE(s):
CVE-2026-44690
CVE-2026-55973
Solution:
Update packages.
CVEs:
CVE-2026-44690
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.
CVE-2026-55973
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.
Additional Info:
N/A
Download:
SRPMS
- unbound-1.24.2-3.el9_8.4.src.rpm
MD5: 8e18777adef7f59691672f21b764b1c9
SHA-256: 28e1c7e71fd725be8dc1d28870ac1652a8e63d1f904f172797c4d2ece82b1f90
Size: 6.68 MB
Asianux Server 9 for x86_64
- python3-unbound-1.24.2-3.el9_8.4.x86_64.rpm
MD5: 766c1cfb372a3abf2e120b77bbb4647e
SHA-256: 32047af294067bbffe54d928115631b67b1cf8b6f68c6d4351dcb906b686bd03
Size: 106.88 kB - unbound-1.24.2-3.el9_8.4.x86_64.rpm
MD5: ea1399a86549dfc76694b4a101acb228
SHA-256: 2b5ff4afc490294cee8ba5ae22267723bcede649afbe56698172f634691c0af0
Size: 1.05 MB - unbound-devel-1.24.2-3.el9_8.4.i686.rpm
MD5: 70d4a18dada6dac52a89b85cded24d7d
SHA-256: 7e97aa94df0736b7207219004552eb52704917a27a8ed65dd666d312bbdc17d0
Size: 37.08 kB - unbound-devel-1.24.2-3.el9_8.4.x86_64.rpm
MD5: 85b59cf63ebe5131d895fbdbfc688e06
SHA-256: 948e9c0a96eac9315e3a63e9d504234b7b6aacff4848097d087d52e7fa725314
Size: 37.07 kB - unbound-dracut-1.24.2-3.el9_8.4.x86_64.rpm
MD5: a540e1ea3aea6a0d25888d6f5a2a03c7
SHA-256: 82939a025f4fc83c8dae4e75e6771b06a0dbd818059dd9f90a86d8499c0a625a
Size: 7.94 kB - unbound-libs-1.24.2-3.el9_8.4.i686.rpm
MD5: d87bb1615b5a5290c7b95819c1317e27
SHA-256: a5402a938cb17213667d6d562558a317a94f9b8426672d06ac229f011a8bc8c3
Size: 606.64 kB - unbound-libs-1.24.2-3.el9_8.4.x86_64.rpm
MD5: a914e26fd1c5243ce56038ec1e837699
SHA-256: e6edf82e4312e4e2090226697f7a7fb5ae5d8621ba20446c6e86e0df92dacdc6
Size: 581.82 kB