Back to Security Advisories
High 2026-07-31

Unbound Security Update — AlmaLinux 8 (ALSA-2026:37282)

AlmaLinux 8

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

Type:
security

Severity:
important

Release date:
2026-07-31

Description:
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets (CVE-2026-44390)
* unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic (CVE-2026-42534)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 unbound-devel-1.16.2-5.12.el8_10.aarch64.rpm 2605c741d5373e5b2620a4035f98a2da1de7b9f554e011108337d2862e101c2c
aarch64 unbound-libs-1.16.2-5.12.el8_10.aarch64.rpm 6c5432fe0ed5a818e315071669bfaf8695058e3e5c19b9a8d4c028687f96fa0e
aarch64 unbound-1.16.2-5.12.el8_10.aarch64.rpm 7bc48a7deb632c4a4b7af46d3d900e8d649ab3025637efc7dfa3a04fe34d799f
aarch64 python3-unbound-1.16.2-5.12.el8_10.aarch64.rpm a865f25444f86774b78b5ac308b88c393530db829cf7865ca2c4d47994635862
i686 unbound-libs-1.16.2-5.12.el8_10.i686.rpm bf0a7e85011cb97fa31c91e4243e4e2b3a2ebda00a3e6bcc623adfabd9746a27
i686 unbound-devel-1.16.2-5.12.el8_10.i686.rpm d78a6b6638fec75478fb04375009ce9457e099a7827b235e72469be677fc8d12
ppc64le unbound-devel-1.16.2-5.12.el8_10.ppc64le.rpm 0c5ad56df3dc2f3766ce62940caabd120ba3a412eb933c814e7aba9abcea7963
ppc64le unbound-1.16.2-5.12.el8_10.ppc64le.rpm 34811831d163b738a57f81ad574562874eca4d561f4fdfb2cd4c056041c6071c
ppc64le unbound-libs-1.16.2-5.12.el8_10.ppc64le.rpm 806dc44111a7a26018621960a03304b4f5eb4ba4da8f3132dafbf4a45ed41bbf
ppc64le python3-unbound-1.16.2-5.12.el8_10.ppc64le.rpm 80d9569b7cf8758af3ccea23a5852ce4914d5778ba531c069e58164cc5d30da1
s390x unbound-devel-1.16.2-5.12.el8_10.s390x.rpm 39cd7028237276f1c9fe35ff94e26ffa632f88568649280d129c302fc877aa90
s390x python3-unbound-1.16.2-5.12.el8_10.s390x.rpm 9bd47b717cc12684bf93046c184cccb92d5ba0310f9b32c7c9c118b38adeed7f
s390x unbound-libs-1.16.2-5.12.el8_10.s390x.rpm affc58cef768b6d0e5a381ca8af7d08e7573b2cc61914706c1933c592a98641b
s390x unbound-1.16.2-5.12.el8_10.s390x.rpm cf36f0a88a35fcc6cda976773564f283a23c721930490ee9715060ecc0f3cd5d
x86_64 python3-unbound-1.16.2-5.12.el8_10.x86_64.rpm 46bf5703a19b0116303198beb1ad2d79f41cf7619cdc328ce8aacb55fb2a4b6a
x86_64 unbound-libs-1.16.2-5.12.el8_10.x86_64.rpm 649d58b39289a966faa5036331cd862f3dd6a9b02cf4e9b264e5e9b07c674156
x86_64 unbound-1.16.2-5.12.el8_10.x86_64.rpm df2864c14264836babda10cb6d61304c5fbbfc35587e167360276fa91537ecb5
x86_64 unbound-devel-1.16.2-5.12.el8_10.x86_64.rpm eea252b01843791b20e9bc57d260329dbc30fbb9a3c2e3ca4860ba20d7b478c5

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

Check Your System