The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.
Security Fix(es):
unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis (CVE-2026-82717)
unbound: Unbound: Heap buffer overflow via malicious DNSSEC response (CVE-2026-81634)
unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY (CVE-2026-81642)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"license": "CC-BY-4.0",
"license_url": "https://creativecommons.org/licenses/by/4.0/",
"source_advisory": "RHSA-2026:70754"
}