RHSA-2026:53402: Important: ldns security update
Important: ldns security update
Other sources
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.Security Fix(es): ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/ldns-develto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-docto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-utilsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/perl-ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/python3-ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1 - Upgrade
Upgrade
redhat/ldns-develto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/ldns-utilsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/perl-ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
redhat/python3-ldnsto a version that resolves this vulnerability.Fixed in 1.8.3-18.el10_0.1.aa - Upgrade
Upgrade
ldnsto a version that resolves this vulnerability.Patch CVE-2026-10846
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:53402?
The severity of RHSA-2026:53402 is categorized as high with a score of 7.
How do I fix RHSA-2026:53402?
To fix RHSA-2026:53402, you need to update the affected ldns packages to the latest version provided by Red Hat.
What does the RHSA-2026:53402 vulnerability affect?
RHSA-2026:53402 affects the ldns library used for DNS programming in C.
What types of packages are included in RHSA-2026:53402?
RHSA-2026:53402 includes updates for ldns, ldns-debuginfo, ldns-devel, and ldns-utils packages among others.
Why is it important to address RHSA-2026:53402?
Addressing RHSA-2026:53402 is important because it resolves security vulnerabilities that could potentially be exploited in DNS operations.