RHSA-2024:0982: Important: unbound security update
Important: unbound security update
Other sources
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/unboundto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/python3-unboundto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/python3-unbound-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/unbound-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/unbound-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/unbound-develto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/unbound-libsto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/unbound-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1 - Upgrade
Upgrade
redhat/python3-unboundto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/python3-unbound-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unboundto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unbound-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unbound-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unbound-develto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unbound-libsto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa - Upgrade
Upgrade
redhat/unbound-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.2-5.el8_8.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0982?
The severity of RHSA-2024:0982 is classified as Important.
What does RHSA-2024:0982 address?
RHSA-2024:0982 addresses a security issue in the unbound DNS resolver related to extreme CPU consumption in the DNSSEC validator.
How do I fix RHSA-2024:0982?
To fix RHSA-2024:0982, you need to upgrade the unbound package to version 1.16.2-5.el8_8.1 or later.
Which software versions are affected by RHSA-2024:0982?
RHSA-2024:0982 affects unbound versions below 1.16.2-5.el8_8.1.
What is the recommended action for users affected by RHSA-2024:0982?
Affected users should apply the security update as soon as possible to mitigate potential risks.