RHSA-2026:54377: Important: ldns security update
Important: ldns security update
Other sources
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.Security Fix(es): ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1 - Upgrade
Upgrade
redhat/ldnsto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
redhat/ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
redhat/ldns-debugsourceto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
redhat/ldns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
redhat/perl-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
redhat/python3-ldns-debuginfoto a version that resolves this vulnerability.Fixed in 1.7.1-11.el9_2.1.aa - Upgrade
Upgrade
ldnsto a version that resolves this vulnerability.Patch CVE-2026-10846
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54377?
The severity of RHSA-2026:54377 is classified as high with a score of 7.
What does the ldns security update in RHSA-2026:54377 address?
The ldns security update in RHSA-2026:54377 addresses vulnerabilities in the ldns library that supports DNS programming in C.
How do I fix RHSA-2026:54377?
To fix RHSA-2026:54377, update the ldns packages to the latest version provided by Red Hat.
Which systems are affected by RHSA-2026:54377?
RHSA-2026:54377 affects Red Hat Enterprise Linux for x86_64 and IBM z Systems.
Is there a known issue associated with RHSA-2026:54377?
Yes, there are known issues associated with RHSA-2026:54377, as detailed in Bugzilla Red Hat report 2487437.