The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292)
unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622)
unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets (CVE-2026-44390)
unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic (CVE-2026-42534)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:1.24.2-7.el10_2.2Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:HA:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N