RHSA-2024:0965: Important: unbound security update
Important: unbound security update
Other sources
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0965?
RHSA-2024:0965 is rated as an important security update.
How do I fix RHSA-2024:0965?
To fix RHSA-2024:0965, update the unbound package to version 1.16.2-5.el8_9.2 or later.
Which packages are affected by RHSA-2024:0965?
The affected packages include unbound, python3-unbound, and several associated libraries and debug packages.
Is there a specific version I need to upgrade to for RHSA-2024:0965?
You need to upgrade to version 1.16.2-5.el8_9.2 or higher to resolve the vulnerabilities in RHSA-2024:0965.
What platforms are impacted by RHSA-2024:0965?
RHSA-2024:0965 impacts Red Hat Enterprise Linux for x86_64, ARM 64, Power, and IBM z Systems.