<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:42:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7622 — Moderate: unbound security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7622</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: unbound (1.16.2). (BZ#2027735)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: the novel ghost domain where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30698)
* unbound: novel ghost domain attack where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30699)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: unbound (1.16.2). (BZ#2027735)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* unbound: the novel ghost domain where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30698)
* unbound: novel ghost domain attack where malicious users to trigger continued resolvability of malicious domain names (CVE-2022-30699)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7622</guid>
    </item>
    <item>
      <title>bdu:2023-03845</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03845</link>
      <description>bdu:2023-03845</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03845</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-168076</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-168076</link>
      <description>EUVD-2026-168076</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-168076</guid>
    </item>
    <item>
      <title>fkie_cve-2022-30699</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30699</link>
      <description>&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-30699</guid>
    </item>
    <item>
      <title>GHSA-fjfh-84xh-5hv3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjfh-84xh-5hv3</link>
      <description>&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjfh-84xh-5hv3</guid>
    </item>
    <item>
      <title>gsd-2022-30699</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-30699</link>
      <description>gsd-2022-30699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-30699</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-30699 — Novel "ghost domain names" attack by updating almost expired delegation information</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-30699</link>
      <description>msrc_CVE-2022-30699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-30699</guid>
    </item>
    <item>
      <title>OESA-2022-1836 — unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1836</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP3: unbound, openEuler:22.03-LTS: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards.To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows.Unbound is a totally free, open source software under the BSD license. It doesn&amp;#39;tmake custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the &amp;amp;quot;ghost domain names&amp;amp;quot; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound&amp;amp;apos;s delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.(CVE-2022-30698)&#13;
&#13;
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;amp;quot;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP3: unbound, openEuler:22.03-LTS: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards.To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows.Unbound is a totally free, open source software under the BSD license. It doesn&amp;#39;tmake custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the &amp;amp;quot;ghost domain names&amp;amp;quot; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound&amp;amp;apos;s delegation cache. This action can be repeated before expiry of the delegation information by querying Unbound for a second level subdomain which the rogue nameserver provides new delegation information. Since Unbound is a child-centric resolver, the ever-updating child delegation information can keep a rogue domain name resolvable long after revocation. From version 1.16.2 on, Unbound checks the validity of parent delegation records before using cached delegation information.(CVE-2022-30698)&#13;
&#13;
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;amp;quot;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1836</guid>
    </item>
    <item>
      <title>RHSA-2022:7622 — Red Hat Security Advisory: unbound security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7622</link>
      <description>&lt;p&gt;unbound: integer overflow in the regional allocator via the ALIGN_UP macro unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: integer overflow in the regional allocator via the ALIGN_UP macro unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7622</guid>
    </item>
    <item>
      <title>RHSA-2024:2045 — Red Hat Security Advisory: unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2045</link>
      <description>&lt;p&gt;unbound: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack) unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack) unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names unbound: novel ghost domain attack that allows attackers to trigger continued resolvability of malicious domain names&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2045</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1923-1 — Security update for unbound</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1923-1</link>
      <description>&lt;p&gt;Security update for unbound&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for unbound&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1923-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-30699</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30699</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:18.04:LTS: unbound, Ubuntu:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:18.04:LTS: unbound, Ubuntu:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the &amp;#34;ghost domain names&amp;#34; attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30699</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2044 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044</guid>
    </item>
  </channel>
</rss>
