[CLSA-2026:1779960466] unbound: Fix of CVE-2026-42960
Type:
security
Severity:
Critical
Release date:
2026-05-28 09:27:50 UTC
Description:
- CVE-2026-42960: fix cache poisoning attack where promiscuous non-NS RRSets with companion glue in the authority section could cause unrelated address records to be cached as a side effect of the query
Updated packages:
  • python3-unbound-1.16.2-5.el8.tuxcare.els6.x86_64.rpm
    sha:514b1270e6f488eb8753674862bf6c43424dd0dde15b73590a904ee69bf52fbd
  • unbound-1.16.2-5.el8.tuxcare.els6.x86_64.rpm
    sha:67c74eaee94a829a865a8341fe1efd519b8d822562208a15b7f2b3abbf47abda
  • unbound-devel-1.16.2-5.el8.tuxcare.els6.i686.rpm
    sha:20c10ef5ef92ef5f0c3d46c6b46c0506074bd7bef14df7988f92d2118912598c
  • unbound-devel-1.16.2-5.el8.tuxcare.els6.x86_64.rpm
    sha:e6627c372cb019acdfc3db1a4f6f8c8482328887e8552134c1c7217cc9b194ef
  • unbound-libs-1.16.2-5.el8.tuxcare.els6.i686.rpm
    sha:788dd7a7a8e55bef72bb4c18337d62b9bb5d7ce17a104c078bc26f32eb0f6a86
  • unbound-libs-1.16.2-5.el8.tuxcare.els6.x86_64.rpm
    sha:5a0fe5aa1dfff25cefe037d92de2d34194802e928593fe3fb77e44baef04527e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.