[CLSA-2026:1785410442] unbound: Fix of CVE-2026-50252
Type:
security
Severity:
Critical
Release date:
2026-07-30 12:10:17 UTC
Description:
- CVE-2026-50252: DNS cache poisoning via per-thread source port partitioning; with 'so-reuseport: yes' and multiple threads the outgoing source port revealed the worker thread, lowering effective port entropy
CVEs fixed:
Updated packages:
  • unbound-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:98f67867534b0ce987d0fcec85299b1a4e161a857f020948b44a773c781f3324
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:efa3ea610fd0bb81bb0ee87a90bc3fc7ea3e52a3036e727ac55ed4f59946bbd3
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:6830c0d8b9e0e6664ea4f337939f8248fed5419cda73f1d6c24e283ae5eabab3
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:180f52678a6f93432dfaff5fae02544011b5e3fafa4d4e4efc9407a21c588131
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:848c0963a674a150d7d4c73c933512415231fadab57453b8cecec67141fabf88
  • unbound-python-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:d7b741e850cd06c33e5ec62fbbff90442e2cbeda21f3f205140465ac6da382b7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.