RHSA-2024:11003: Important: unbound security update
Important: unbound security update
Other sources
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. <br>Security Fix(es):<br><li> bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387)</li> <li> bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:11003?
The severity of RHSA-2024:11003 is classified as important.
What vulnerabilities are addressed in RHSA-2024:11003?
RHSA-2024:11003 addresses vulnerabilities including CVE-2023-50387 which causes extreme CPU consumption in the DNSSEC validator.
How do I fix RHSA-2024:11003?
To fix RHSA-2024:11003, update the unbound package to version 1.6.6-5.el7_9.1.
Which products are affected by RHSA-2024:11003?
RHSA-2024:11003 affects multiple variants of Red Hat Enterprise Linux Server, including Extended Life Cycle Support for various architectures.
Is a restart required after applying the fix for RHSA-2024:11003?
Generally, a restart of the unbound service is recommended after applying the fix for RHSA-2024:11003.