[CLSA-2026:1780478142] unbound: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-06-03 09:15:57 UTC
Description:
- rebase onto Amazon Linux 2 1.7.3-15.amzn2.0.14 (CVE-2026-42959, CVE-2026-42960, CVE-2026-44390, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-33278); take AL2's six new bug-fix patches; keep the TuxCare CVE-2019-16866 and CVE-2026-33278 backports (renumbered to Patch1016/1017). Our CVE-2026-33278 fix is kept over AL2's because it is a superset: it adds the defense-in-depth NSEC3 parameter consistency check (param_set_same) on top of the same dns_msg_deepcopy_region use-after-free fix. No new TuxCare ELS work ships here.
Updated packages:
  • python2-unbound-1.7.3-15.amzn2.0.14.tuxcare.els1.x86_64.rpm
    sha:1a04bcc007f2f6dbe404af2dc1e30d2478f524f83410b573d2d915a859d29aab
  • python3-unbound-1.7.3-15.amzn2.0.14.tuxcare.els1.x86_64.rpm
    sha:0a916a21980a1041e686eb1bcf32f25deb229ae83ca0f2d5a877c27cdea36682
  • unbound-1.7.3-15.amzn2.0.14.tuxcare.els1.x86_64.rpm
    sha:1ac15641bc6a8a07998c0e39d4df563f3e60e14886a69f20636e08153f1ccf11
  • unbound-devel-1.7.3-15.amzn2.0.14.tuxcare.els1.x86_64.rpm
    sha:7f81b213c0bc9e1a4142c4ab4d491fe6cd92d3863051fdc6b014e9cf46651bb1
  • unbound-libs-1.7.3-15.amzn2.0.14.tuxcare.els1.i686.rpm
    sha:913c487d816bfd5fc99f7fdefaca27f64d08473c1a0e016c1d25caa3171f870e
  • unbound-libs-1.7.3-15.amzn2.0.14.tuxcare.els1.x86_64.rpm
    sha:f7be0ad1294eb824dd0d8be59c85e24ef32dcb2ace55e0f498c3b3ca7e06404f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.