Issued:
2024-04-25
Updated:
2024-04-25

RHSA-2024:2045 - Moderate: unbound security update


Synopsis

Moderate: unbound security update

Type/Severity

Security Advisory: Moderate

Topic

An update for unbound is now available for Red Hat Enterprise Linux 8.6 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack) (CVE-2022-3204)

  • unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names (CVE-2022-30699)

  • unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names (CVE-2022-30698)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions8.6x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support8.6x86_64
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life8.6x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support8.6ppc64le
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support8.6s390x
Red Hat Enterprise Linux for ARM 64 - Extended Update Support8.6aarch64
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions8.6ppc64le
Red Hat Enterprise Linux Server - TUS8.6x86_64
Red Hat Enterprise Linux Server - AUS8.6x86_64

Updated Packages

  • unbound-debugsource-1.7.3-17.el8_6.5.i686.rpm
  • unbound-libs-debuginfo-1.7.3-17.el8_6.5.i686.rpm
  • unbound-libs-debuginfo-1.7.3-17.el8_6.5.x86_64.rpm
  • python3-unbound-debuginfo-1.7.3-17.el8_6.5.ppc64le.rpm
  • unbound-devel-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-debuginfo-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-debugsource-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-libs-1.7.3-17.el8_6.5.i686.rpm
  • unbound-libs-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-libs-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-debuginfo-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-1.7.3-17.el8_6.5.ppc64le.rpm
  • python3-unbound-debuginfo-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-libs-1.7.3-17.el8_6.5.ppc64le.rpm
  • python3-unbound-debuginfo-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-debuginfo-1.7.3-17.el8_6.5.i686.rpm
  • python3-unbound-1.7.3-17.el8_6.5.x86_64.rpm
  • python3-unbound-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-devel-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-libs-debuginfo-1.7.3-17.el8_6.5.aarch64.rpm
  • python3-unbound-1.7.3-17.el8_6.5.ppc64le.rpm
  • unbound-debugsource-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-debuginfo-1.7.3-17.el8_6.5.ppc64le.rpm
  • unbound-devel-1.7.3-17.el8_6.5.s390x.rpm
  • python3-unbound-debuginfo-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-libs-debuginfo-1.7.3-17.el8_6.5.ppc64le.rpm
  • unbound-debugsource-1.7.3-17.el8_6.5.ppc64le.rpm
  • unbound-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-devel-1.7.3-17.el8_6.5.i686.rpm
  • python3-unbound-debuginfo-1.7.3-17.el8_6.5.i686.rpm
  • unbound-debuginfo-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-devel-1.7.3-17.el8_6.5.ppc64le.rpm
  • python3-unbound-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-libs-1.7.3-17.el8_6.5.aarch64.rpm
  • unbound-libs-debuginfo-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-1.7.3-17.el8_6.5.x86_64.rpm
  • unbound-debugsource-1.7.3-17.el8_6.5.s390x.rpm
  • unbound-1.7.3-17.el8_6.5.src.rpm

Fixes

CVEs

References


Additional information