<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:43:31.585076+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7622</id>
    <title>ALSA-2022:7622 — Moderate: unbound security, bug fix, and enhancement update</title>
    <updated>2026-10-07T22:43:31.606506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs</p>
<p>The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.</p>
<p>The following packages have been upgraded to a later upstream version: unbound (1.16.2). (BZ#2027735)</p>
<p>Security Fix(es):</p>
<p>* unbound: the novel ghost domain where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30698)
* unbound: novel ghost domain attack where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30699)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03845</id>
    <title>bdu:2023-03845</title>
    <updated>2026-10-07T22:43:31.606578+00:00</updated>
    <content>bdu:2023-03845</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03845"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-07T22:43:31.606596+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-168076</id>
    <title>EUVD-2026-168076</title>
    <updated>2026-10-07T22:43:31.606612+00:00</updated>
    <content>EUVD-2026-168076</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-168076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30699</id>
    <title>fkie_cve-2022-30699</title>
    <updated>2026-10-07T22:43:31.606622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-30699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fjfh-84xh-5hv3</id>
    <title>GHSA-fjfh-84xh-5hv3</title>
    <updated>2026-10-07T22:43:31.606649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fjfh-84xh-5hv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-30699</id>
    <title>gsd-2022-30699</title>
    <updated>2026-10-07T22:43:31.606668+00:00</updated>
    <content>gsd-2022-30699</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-30699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-30699</id>
    <title>msrc_CVE-2022-30699 — Novel "ghost domain names" attack by updating almost expired delegation information</title>
    <updated>2026-10-07T22:43:31.606678+00:00</updated>
    <content>msrc_CVE-2022-30699</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-30699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1836</id>
    <title>OESA-2022-1836 — unbound security update</title>
    <updated>2026-10-07T22:43:31.606692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP3: unbound, openEuler:22.03-LTS: unbound</p>
<p>Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards.To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows.Unbound is a totally free, open source software under the BSD license. It doesn'tmake custom builds or provide specific features to paying customers only.

Security Fix(es):

NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the &amp;quot;ghost domain names&amp;quot; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound&amp;apos;s delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.(CVE-2022-30698)

NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;quot;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7622</id>
    <title>RHSA-2022:7622 — Red Hat Security Advisory: unbound security, bug fix, and enhancement update</title>
    <updated>2026-10-07T22:43:31.606732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>unbound: integer overflow in the regional allocator via the ALIGN_UP macro unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2045</id>
    <title>RHSA-2024:2045 — Red Hat Security Advisory: unbound security update</title>
    <updated>2026-10-07T22:43:31.606752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>unbound: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack) unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1923-1</id>
    <title>SUSE-SU-2024:1923-1 — Security update for unbound</title>
    <updated>2026-10-07T22:43:31.606769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for unbound</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1923-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30699</id>
    <title>UBUNTU-CVE-2022-30699</title>
    <updated>2026-10-07T22:43:31.606784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:18.04:LTS: unbound, Ubuntu:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound</p>
<p>NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044</id>
    <title>WID-SEC-W-2022-2044 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-07T22:43:31.606812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044"/>
  </entry>
</feed>
