RHSA-2026:50108: Important: ldns security update
Important: ldns security update
Other sources
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.Security Fix(es): ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/ldns-develto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-docto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-utilsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/perl-ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/python3-ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1 - Upgrade
Upgrade
redhat/ldns-develto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/ldns-utilsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/perl-ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa - Upgrade
Upgrade
redhat/python3-ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-12.el9_8.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50108?
The severity of RHSA-2026:50108 is classified as high, with a score of 7.
What software packages are affected by RHSA-2026:50108?
The affected software packages include redhat/ldns, redhat/ldns-debuginfo, redhat/ldns-debugsource, redhat/ldns-utils-debuginfo, redhat/perl-ldns-debuginfo, redhat/python3-ldns-debuginfo, redhat/ldns-devel, and redhat/ldns-utils.
How do I fix RHSA-2026:50108?
To fix RHSA-2026:50108, you need to update the affected ldns packages to their latest versions provided by Red Hat.
What does the ldns library do related to RHSA-2026:50108?
The ldns library simplifies DNS programming in C, supporting low-level DNS/DNSSEC operations and providing a higher-level API for managing DNS packets.
When was RHSA-2026:50108 published?
RHSA-2026:50108 was published on August 4, 2026.