[CLSA-2026:1780509244] unbound: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-03 17:54:20 UTC
Description:
- CVE-2025-11411: scrub promiscuous NS RRsets from positive answers to prevent a possible domain hijacking attack; add the iter-scrub-promiscuous option (default yes) and extend the mitigation to YXDOMAIN and non-referral nodata answers
Updated packages:
  • python3-unbound-1.16.2-3.el9_2.tuxcare.els8.x86_64.rpm
    sha:b0e8ed4c805f88a60d7ca17773227f9a3b9a2b488252d7196fc9ad4b1570c5af
  • unbound-1.16.2-3.el9_2.tuxcare.els8.x86_64.rpm
    sha:f3ca6dcdf898e944c6b375bc11e0de58c0474e1078e343437bad4f10833fc94a
  • unbound-devel-1.16.2-3.el9_2.tuxcare.els8.i686.rpm
    sha:93ab75dbf33fcace4a8bc56d51e41e951d0904e6e0fa71637db4653b7ab25e14
  • unbound-devel-1.16.2-3.el9_2.tuxcare.els8.x86_64.rpm
    sha:07899722eb249f91eab2752af3eff9678417e8f4657a101ff6a53c5b94506b95
  • unbound-libs-1.16.2-3.el9_2.tuxcare.els8.i686.rpm
    sha:f36ce276aea13c32de215be7b2ef76dec6b15f40559669443985af096a28e835
  • unbound-libs-1.16.2-3.el9_2.tuxcare.els8.x86_64.rpm
    sha:efd65c96e8d85c130e9da2e66e3e567fe1fe2043bed3fa3f73ec73c3e4ba71b7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.