Unbound Security Update — AlmaLinux 8 (ALSA-2026:37282)
This is a security release for AlmaLinux 8. The fix ships in the current release line (referenced builds: 16.2-5). Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Команды исправления
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in AlmaLinux 8 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial…
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial…
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial…
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial…
Type:
security
Severity:
important
Release date:
2026-07-31
Description:
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
* unbound: Unbound: Cache manipulation via ‘ghost domain names’ attack (CVE-2026-40622)
* unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets (CVE-2026-44390)
* unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic (CVE-2026-42534)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
Updated packages listed below:
| Architecture | Package | Checksum |
| aarch64 | unbound-devel-1.16.2-5.12.el8_10.aarch64.rpm | 2605c741d5373e5b2620a4035f98a2da1de7b9f554e011108337d2862e101c2c |
| aarch64 | unbound-libs-1.16.2-5.12.el8_10.aarch64.rpm | 6c5432fe0ed5a818e315071669bfaf8695058e3e5c19b9a8d4c028687f96fa0e |
| aarch64 | unbound-1.16.2-5.12.el8_10.aarch64.rpm | 7bc48a7deb632c4a4b7af46d3d900e8d649ab3025637efc7dfa3a04fe34d799f |
| aarch64 | python3-unbound-1.16.2-5.12.el8_10.aarch64.rpm | a865f25444f86774b78b5ac308b88c393530db829cf7865ca2c4d47994635862 |
| i686 | unbound-libs-1.16.2-5.12.el8_10.i686.rpm | bf0a7e85011cb97fa31c91e4243e4e2b3a2ebda00a3e6bcc623adfabd9746a27 |
| i686 | unbound-devel-1.16.2-5.12.el8_10.i686.rpm | d78a6b6638fec75478fb04375009ce9457e099a7827b235e72469be677fc8d12 |
| ppc64le | unbound-devel-1.16.2-5.12.el8_10.ppc64le.rpm | 0c5ad56df3dc2f3766ce62940caabd120ba3a412eb933c814e7aba9abcea7963 |
| ppc64le | unbound-1.16.2-5.12.el8_10.ppc64le.rpm | 34811831d163b738a57f81ad574562874eca4d561f4fdfb2cd4c056041c6071c |
| ppc64le | unbound-libs-1.16.2-5.12.el8_10.ppc64le.rpm | 806dc44111a7a26018621960a03304b4f5eb4ba4da8f3132dafbf4a45ed41bbf |
| ppc64le | python3-unbound-1.16.2-5.12.el8_10.ppc64le.rpm | 80d9569b7cf8758af3ccea23a5852ce4914d5778ba531c069e58164cc5d30da1 |
| s390x | unbound-devel-1.16.2-5.12.el8_10.s390x.rpm | 39cd7028237276f1c9fe35ff94e26ffa632f88568649280d129c302fc877aa90 |
| s390x | python3-unbound-1.16.2-5.12.el8_10.s390x.rpm | 9bd47b717cc12684bf93046c184cccb92d5ba0310f9b32c7c9c118b38adeed7f |
| s390x | unbound-libs-1.16.2-5.12.el8_10.s390x.rpm | affc58cef768b6d0e5a381ca8af7d08e7573b2cc61914706c1933c592a98641b |
| s390x | unbound-1.16.2-5.12.el8_10.s390x.rpm | cf36f0a88a35fcc6cda976773564f283a23c721930490ee9715060ecc0f3cd5d |
| x86_64 | python3-unbound-1.16.2-5.12.el8_10.x86_64.rpm | 46bf5703a19b0116303198beb1ad2d79f41cf7619cdc328ce8aacb55fb2a4b6a |
| x86_64 | unbound-libs-1.16.2-5.12.el8_10.x86_64.rpm | 649d58b39289a966faa5036331cd862f3dd6a9b02cf4e9b264e5e9b07c674156 |
| x86_64 | unbound-1.16.2-5.12.el8_10.x86_64.rpm | df2864c14264836babda10cb6d61304c5fbbfc35587e167360276fa91537ecb5 |
| x86_64 | unbound-devel-1.16.2-5.12.el8_10.x86_64.rpm | eea252b01843791b20e9bc57d260329dbc30fbb9a3c2e3ca4860ba20d7b478c5 |
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему