RHSA-2024:0981: Important: unbound security update
Important: unbound security update
Other sources
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0981?
RHSA-2024:0981 has been classified as important due to the potential for extreme CPU consumption by the DNSSEC validator.
How do I fix RHSA-2024:0981?
To fix RHSA-2024:0981, update the unbound package to version 1.16.2-3.el9_2.1 or later.
Which systems are affected by RHSA-2024:0981?
RHSA-2024:0981 affects multiple Red Hat Enterprise Linux systems including versions for x86_64, ARM, and Power architectures.
What specific vulnerabilities are addressed in RHSA-2024:0981?
RHSA-2024:0981 addresses an issue with extreme CPU consumption in the DNSSEC validator, identified as CVE-2023-50387.
Is there a specific package version required for RHSA-2024:0981?
Yes, you need to install unbound version 1.16.2-3.el9_2.1 to mitigate the vulnerabilities associated with RHSA-2024:0981.