Synopsis
Critical: unbound security update
Description
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
* unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis (CVE-2026-82717)
* unbound: Unbound: Heap buffer overflow via malicious DNSSEC response (CVE-2026-81634)
* unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY (CVE-2026-81642)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected products
Rocky Linux 8 aarch64
Rocky Linux 8 x86_64
Fixes
2535051
2535054
2535059
CVEs
CVE-2026-81634
CVE-2026-81642
CVE-2026-82717
Affected packages
Rocky Linux 8 aarch64 - AppStream
python3-unbound-0:1.16.2-5.14.el8_10.4.aarch64.rpm
python3-unbound-debuginfo-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-0:1.16.2-5.14.el8_10.4.src.rpm
unbound-debuginfo-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-debugsource-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-devel-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-libs-0:1.16.2-5.14.el8_10.4.aarch64.rpm
unbound-libs-debuginfo-0:1.16.2-5.14.el8_10.4.aarch64.rpm
Rocky Linux 8 x86_64 - AppStream
python3-unbound-0:1.16.2-5.14.el8_10.4.x86_64.rpm
python3-unbound-debuginfo-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-0:1.16.2-5.14.el8_10.4.src.rpm
unbound-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-debuginfo-0:1.16.2-5.14.el8_10.4.i686.rpm
unbound-debuginfo-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-debugsource-0:1.16.2-5.14.el8_10.4.i686.rpm
unbound-debugsource-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-devel-0:1.16.2-5.14.el8_10.4.i686.rpm
unbound-devel-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-libs-0:1.16.2-5.14.el8_10.4.i686.rpm
unbound-libs-0:1.16.2-5.14.el8_10.4.x86_64.rpm
unbound-libs-debuginfo-0:1.16.2-5.14.el8_10.4.i686.rpm
unbound-libs-debuginfo-0:1.16.2-5.14.el8_10.4.x86_64.rpm