RHSA-2026:36782: Moderate: aardvark-dns security update
Authoritative DNS server for A/AAAA container records Forwards other request to configured resolvers. Read more about configuration in src/backend/mod.rs.Security Fix(es): aardvark-dns: Aardvark-dns: Denial of Service via truncated TCP DNS query and connection reset (CVE-2026-35406) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2 - Upgrade
Upgrade
redhat/aardvark-dns-debuginfoto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2 - Upgrade
Upgrade
redhat/aardvark-dns-debugsourceto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2 - Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2.aa - Upgrade
Upgrade
redhat/aardvark-dns-debuginfoto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2.aa - Upgrade
Upgrade
redhat/aardvark-dns-debugsourceto a version that resolves this vulnerability.Fixed in 1.17.1-1.el10_2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36782?
The severity of RHSA-2026:36782 is classified as medium with a score of 4.
How do I fix RHSA-2026:36782?
To fix RHSA-2026:36782, update the aardvark-dns packages to the latest version provided by Red Hat.
What vulnerability does RHSA-2026:36782 address?
RHSA-2026:36782 addresses a denial of service vulnerability via truncated TCP DNS query and connection reset, identified as CVE-2026-35406.
What products are affected by RHSA-2026:36782?
Affected products by RHSA-2026:36782 include Red Hat Enterprise Linux for various architectures that use the aardvark-dns software.
When was RHSA-2026:36782 published?
RHSA-2026:36782 was published on July 8, 2026.