[CLSA-2026:1785241157] unbound: Fix of CVE-2026-50252
Type:
security
Severity:
Critical
Release date:
2026-07-28 12:19:28 UTC
Description:
- CVE-2026-50252: draw outgoing UDP ports from a shared randomized pool so a source port can no longer be mapped to a worker thread for cache poisoning
CVEs fixed:
Updated packages:
  • python3-unbound-1.16.2-5.el8.tuxcare.els9.x86_64.rpm
    sha:da5223500f127126747248d4c7c2fe29264835b6c5f711387f738abbeca3482b
  • unbound-1.16.2-5.el8.tuxcare.els9.x86_64.rpm
    sha:6c75ee1dab06af955975ada94d0921e40a0bc14f0c74663d6a628f301ad1fb14
  • unbound-devel-1.16.2-5.el8.tuxcare.els9.i686.rpm
    sha:5c1532c3450b611e0dbb0cbb963ec0bbf65e3c875ef1235c069717414070763f
  • unbound-devel-1.16.2-5.el8.tuxcare.els9.x86_64.rpm
    sha:5712865736b3d29a3b4ea0b1a5e1174d5c37de891b580306d611a873bd6a8a8a
  • unbound-libs-1.16.2-5.el8.tuxcare.els9.i686.rpm
    sha:4963e42f8bd3957283ad6d2ab7c28007818cd603e45c2e4873eb527e8a1a9033
  • unbound-libs-1.16.2-5.el8.tuxcare.els9.x86_64.rpm
    sha:2c03e70c9e241509ee02d4fe7cdeff19bf6d9dfc2c09f3c929501d5b3e48dfbc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.