[CLSA-2026:1785409943] unbound: Fix of CVE-2026-50252
Type:
security
Severity:
Critical
Release date:
2026-07-30 13:30:33 UTC
Description:
- CVE-2026-50252: DNS cache poisoning via per-thread source port partitioning; with 'so-reuseport: yes' and multiple threads the outgoing source port revealed the worker thread, lowering effective port entropy
CVEs fixed:
Updated packages:
  • unbound-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:c9a3ac2d64ce4decc0c844d49384c61c110ac2626252ebc62fa1cfbb1f7b6e2f
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:4e7e43ded89230fc068e41a213ee8c2bd731dbc3f7fcedcef6ba8232836eeb49
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:4ed4fefbf7d42e36142682952549e4aa13157742c58be77958a9ffe40dd544ab
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:82493b25852bcf437868076dd17101f74092f409df00e052fc22f213ee78ad94
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:b21202bcd5761da979c6b82699a021569b1a94188315f6cc5b17eac7e8161a7f
  • unbound-python-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:b2852757e381e4e38f9faa9d928c4bcf39bfc88ae9bb4d189229e8f1dc2c92c5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.