RHSA-2026:54244: Important: ldns security update
Important: ldns security update
Other sources
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.Security Fix(es): ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1 - Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_4.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54244?
The severity of RHSA-2026:54244 is high, with a CVSS score of 7.
How do I fix RHSA-2026:54244?
To fix RHSA-2026:54244, update the affected ldns packages to the latest version available from Red Hat.
What software is affected by RHSA-2026:54244?
The affected software includes redhat/ldns, redhat/ldns-debuginfo, redhat/ldns-debugsource, and related packages.
What type of vulnerability does RHSA-2026:54244 address?
RHSA-2026:54244 addresses security vulnerabilities in the ldns library used for DNS programming.
Is there a risk associated with RHSA-2026:54244?
Yes, RHSA-2026:54244 has been assessed with a risk level of 33, indicating potential security implications.