[CLSA-2026:1785412633] unbound: Fix of CVE-2026-50252
Type:
security
Severity:
Critical
Release date:
2026-07-30 11:57:23 UTC
Description:
- CVE-2026-50252: DNS cache poisoning via per-thread source port partitioning; with 'so-reuseport: yes' and multiple threads the outgoing source port revealed the worker thread, lowering effective port entropy
CVEs fixed:
Updated packages:
  • unbound-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:23eb8628053678912e38b419b7e052b506e7753e4bf2f9cbfe7959c5f51507cc
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:e3a9367015f76b3ceb3497a07e5af2eedc617a54dbb20ba3861dbb2ec90104e7
  • unbound-devel-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:c0f602bdeb661ef6c2c2a60502b511ec7c5e39a630defabbf776abdea1873581
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.i686.rpm
    sha:8261d3404a7de9cd002beeab02c4fc33c1062e33b0a8d550e9f795dceae83529
  • unbound-libs-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:670040d2024efdfeca01e4f44379f20dc28d1fe3791b55c4af08f7f76adb6cc2
  • unbound-python-1.6.6-5.el7_8.tuxcare.els7.x86_64.rpm
    sha:bda04ea0c779497c83f397b02b380a215bf7a3ec335f1127e6a9d22f6f0e6219
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.