{
  "threat_severity" : "Important",
  "public_date" : "2026-05-20T09:19:13Z",
  "bugzilla" : {
    "description" : "unbound: Unbound: Denial of Service via excessive EDNS options",
    "id" : "2480125",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2480125"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1050",
  "details" : [ "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).", "A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending queries with an excessive number of EDNS (Extension Mechanisms for DNS) options. This can cause Unbound threads to be held hostage while parsing and creating internal data structures for these options. Coordinated attacks can lead to resource exhaustion, resulting in a degradation of service or a denial of service (DoS) for legitimate users." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-07T00:00:00Z",
    "advisory" : "RHSA-2026:36320",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "unbound-0:1.24.2-7.el10_2.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37282",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "unbound-0:1.16.2-5.12.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36777",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "unbound-0:1.24.2-3.el9_8.2"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.22",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:54769",
    "cpe" : "cpe:/a:redhat:openshift:4.22::el9",
    "package" : "rhcos-4.22.9.8.202608130832-0"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-07T00:00:00Z",
    "advisory" : "RHSA-2026:24013",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "unbound-main-1.25.1-2.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "unboundid-ldapsdk",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Affected",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "unboundid-ldapsdk",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel8-tech-preview/openstack-unbound",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Affected",
    "package_name" : "rhosp-rhel9/openstack-unbound",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Affected",
    "package_name" : "rhoso/openstack-unbound-rhel9",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Affected",
    "package_name" : "rhoso-operators/designate-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-41292\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41292\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.txt" ],
  "name" : "CVE-2026-41292",
  "mitigation" : {
    "value" : "Disclaimer: The following mitigation solutions are provided as a courtesy, pending the application of an official patch. This content was generated utilizing AI tools in conjunction with data from cmetaxonomy.org. Customers are advised to independently evaluate and test these temporary mitigations within their own infrastructure.\nUntil patched, restrict the resolver to authorized client networks via firewall and apply DNS rate limiting per source IP. Service watchdog and cgroup limits provide resilience but are not a substitute for patching.",
    "lang" : "en:us"
  },
  "csaw" : false
}