<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:48:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:55841 — Important: unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:55841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-unbound, AlmaLinux:9: unbound, AlmaLinux:9: unbound-devel, AlmaLinux:9: unbound-dracut, AlmaLinux:9: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)
  * unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option (CVE-2026-55973)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-unbound, AlmaLinux:9: unbound, AlmaLinux:9: unbound-devel, AlmaLinux:9: unbound-dracut, AlmaLinux:9: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)
  * unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option (CVE-2026-55973)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:55841</guid>
    </item>
    <item>
      <title>EUVD-2026-339353</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339353</link>
      <description>EUVD-2026-339353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339353</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55973</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55973</link>
      <description>&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55973</guid>
    </item>
    <item>
      <title>GHSA-g479-fg97-pf5w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g479-fg97-pf5w</link>
      <description>&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g479-fg97-pf5w</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-55973 — 'dns-error-reporting: yes' leads to stack buffer overflow</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-55973</link>
      <description>msrc_CVE-2026-55973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-55973</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11380-1 — libunbound8-1.25.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</link>
      <description>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</guid>
    </item>
    <item>
      <title>RHSA-2026:43588 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:43588</link>
      <description>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:43588</guid>
    </item>
    <item>
      <title>RLSA-2026:55841 — Important: unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:55841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: unbound&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option (CVE-2026-55973)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: unbound&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes (CVE-2026-44690)&lt;/p&gt;
&lt;p&gt;* unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option (CVE-2026-55973)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:55841</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23050-1 — Security update for unbound</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</link>
      <description>&lt;p&gt;Security update for unbound&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for unbound&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-55973</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55973</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when &amp;#39;dns-error-reporting: yes&amp;#39; is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option&amp;#39;s length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic &amp;#39;_er.&amp;#39; report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during &amp;#39;find_closest_of_type()&amp;#39;, it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to &amp;#39;dname_query_hash()&amp;#39; as a label length writing over the stack variable &amp;#39;labuf&amp;#39;. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55973</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2492 — Unbound: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</guid>
    </item>
  </channel>
</rss>
