Back to Security Advisories
High 2026-07-31

Unbound Security Update — AlmaLinux 9 (ALSA-2026:36777)

AlmaLinux 9

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
* unbound: Unbound: Denial…

Type:
security

Severity:
important

Release date:
2026-07-31

Description:
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets (CVE-2026-44390)
* unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic (CVE-2026-42534)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 unbound-libs-1.24.2-3.el9_8.2.aarch64.rpm 47d22578c1452eff87ddb8ec25aae6427a8878f0715512deb78d3435e0309588
aarch64 unbound-dracut-1.24.2-3.el9_8.2.aarch64.rpm 570fb3ff95079dd535d01904a8424bc00461695f2b4496d447c0406b9f752d93
aarch64 unbound-devel-1.24.2-3.el9_8.2.aarch64.rpm 612d17398514ef6953d5075b477cf7261a8ea7255d516011bb94795b29fa7e96
aarch64 python3-unbound-1.24.2-3.el9_8.2.aarch64.rpm 6995e2375819e531eb81224c9a8f2cbc3ade7e4ef367ca421e69432002fac6ba
aarch64 unbound-1.24.2-3.el9_8.2.aarch64.rpm a15ebffe737d9c710018af8a5ab3f189a6c592d6d06614f304f5c423f68073c6
i686 unbound-libs-1.24.2-3.el9_8.2.i686.rpm 48cc80caa9e995510ab8a454a7fb6f02a35851451114ead47eb0b0e79049ac75
i686 unbound-devel-1.24.2-3.el9_8.2.i686.rpm 826d123e67ec0087d4446890e000e192295850a111eacadd1901be1ed47bccee
ppc64le unbound-devel-1.24.2-3.el9_8.2.ppc64le.rpm 1523746fe9cdd6940f0d5b4549e9fb82893994bf592fe2193eb4bf6dc6407151
ppc64le unbound-dracut-1.24.2-3.el9_8.2.ppc64le.rpm 6c54f57fdbd0bbdf07a98c00e54c80f3a98882f96c1dfaadcda661e1f119497e
ppc64le unbound-libs-1.24.2-3.el9_8.2.ppc64le.rpm 77f1a8b484081f3d1d7dd15845c805956617cd3c26468cfa8e6421ee47ea07c8
ppc64le unbound-1.24.2-3.el9_8.2.ppc64le.rpm a13aac14a8e589cc57c3ca37df07ad07d037509eb7debe74910da3c0ec6720c0
ppc64le python3-unbound-1.24.2-3.el9_8.2.ppc64le.rpm fb500916e85afb66dc9980aea90a3f8fb81b2513a72033bd80b49562e600d5da
s390x unbound-dracut-1.24.2-3.el9_8.2.s390x.rpm 578b70938002548735574c16718c58672859596458481e0f15ad3228dc2a3479
s390x unbound-devel-1.24.2-3.el9_8.2.s390x.rpm 83ebffaecfdcc2d38a7f7de6c67036e61efd0d15ddb448f8aa12c6d03ba0c7b7
s390x unbound-1.24.2-3.el9_8.2.s390x.rpm a213061bf88d6e36161e6fc8aa6f36ee243fb10b12687bffc279b215d2932350
s390x python3-unbound-1.24.2-3.el9_8.2.s390x.rpm c0e98171e17554b510f589916358b8625162f28e7ea50122617d30b27ebb4c82
s390x unbound-libs-1.24.2-3.el9_8.2.s390x.rpm fe58379bb7f915c4cd6ecaf76b36aef011859ad0a686e9f18d9908ccf9a432f3
x86_64 unbound-dracut-1.24.2-3.el9_8.2.x86_64.rpm bc771cf8f33d3807e14e2ed1019b85a7679f753a9d62c5edeaae6b42d58b9246
x86_64 python3-unbound-1.24.2-3.el9_8.2.x86_64.rpm c3bcc1c8626ad89c81f77756c156739755341a89b397af61e28605ff72fc92af
x86_64 unbound-devel-1.24.2-3.el9_8.2.x86_64.rpm d19c6041f368608d4cc0d581d8a77a35b157c024c83c194efea4ca39a70656db
x86_64 unbound-libs-1.24.2-3.el9_8.2.x86_64.rpm e03730a14bd0749dacacc8ec5233871b0ad00cf7e2e18489d9b9c03743e8b60f
x86_64 unbound-1.24.2-3.el9_8.2.x86_64.rpm e68d297863fc0358bc1a3c16e4d6ac0edd83622b8f380c6bc4a7b8437f7e7516

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System