unbound-1.16.2-5.14.el8_10.2
エラータID: AXSA:2026-1894:13
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: DNS cache poisoning via UDP source port predictability (CVE-2026-50252)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-50252
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernel’s SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolver’s outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.
Update packages.
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernel’s SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolver’s outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.
N/A
SRPMS
- unbound-1.16.2-5.14.el8_10.2.src.rpm
MD5: 467181ffffe5c20bded8e2079e528360
SHA-256: e5f96cf902570e1e0b9004c7b3ed5dcd1fca3f76f1b90c338b8d81a411155e81
Size: 6.05 MB
Asianux Server 8 for x86_64
- python3-unbound-1.16.2-5.14.el8_10.2.x86_64.rpm
MD5: 91acfac28355050a7f99a4157c991e69
SHA-256: bdb4afd57248229c829846b421924e32a06ef1b0d440995355f2015c7c6a0e5a
Size: 130.00 kB - unbound-1.16.2-5.14.el8_10.2.x86_64.rpm
MD5: 1d785b7d7f8b0411419138b7406f2a54
SHA-256: adb54f0a27f1e0cce5cc65aad13653c2effa49a97b846a4e4824357422cbb465
Size: 1.01 MB - unbound-devel-1.16.2-5.14.el8_10.2.i686.rpm
MD5: 8a0e2c60f247545c163822f1424238c4
SHA-256: 698c1281a26a8e79e4a2ca18f2384cda2cbeb4cdc865aa3ba25923debc625800
Size: 57.62 kB - unbound-devel-1.16.2-5.14.el8_10.2.x86_64.rpm
MD5: 9aec9dcf4954bd157d8b5965890069e0
SHA-256: bebbd07b467d88c18c004c36a410db6a9f20952c38c63b58979973fbd97719e7
Size: 57.61 kB - unbound-libs-1.16.2-5.14.el8_10.2.i686.rpm
MD5: f6f8c0b0c0c7f3d9cf8c29cb6ef77bbc
SHA-256: ca96e99861eaa7b61f5084df30510a9310641dd0263fa105cab44058a6045ce6
Size: 620.77 kB - unbound-libs-1.16.2-5.14.el8_10.2.x86_64.rpm
MD5: 8b404ef776f8af28925a901fd7d19480
SHA-256: 6cb46a6b343b548863517433a68e20dead9228318339b11ac5b5e1d987445955
Size: 580.08 kB