[CLSA-2026:1790953388] unbound: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-10-02 15:03:23 UTC
Description:
- rebase onto Amazon Linux 2 1.7.3-15.amzn2.0.17; take the vendor's three new patches as Patch1020-Patch1022 and renumber the TuxCare patches to Patch1023-Patch1025. The vendor also renamed its 0.16 fix-buffer-overflow.patch to CVE-2026-81642.patch; the diff payload is byte-identical - CVE-2026-81634: add the missing first owner name and signature length bounds checks to rrset_canonical() in validator/val_sigcrypt.c, preventing a heap buffer overflow during RRset canonicalisation - CVE-2026-82717: carry the vendor's defence-in-depth bounds checks - restore the packet-buffer position on every malformed-name failure in pkt_dname_len(), and validate decompressed-name lengths, packet progress and the trailing copy length in rdata_copy(). 1.7.3 is not affected by the CNAME synthesis write itself: synth_cname_rrset() allocates its own storage with TTL zero and has no cache-min/cache-max rewrite through ttl_data into packet bytes - CVE-2026-85501: bound the DNSSEC work a single query may cause - key-tag matches capped at MAX_TAG_MATCHES (256), NSEC/NSEC3 verifications at MAX_VALIDATE_NSECS (8) per message, and new val-validation-attempts and val-hash-attempts options (default 32) capping signature verifications and DS hash computations per validator query state; oversized referral DS RRsets are shortened in the scrubber and val-clean-additional now defaults to no - keep the TuxCare CVE-2019-16866, CVE-2026-50252 and CVE-2026-33278 (NSEC3 half) backports
Updated packages:
  • python2-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.aarch64.rpm
    sha:d04b484d8efebf785ff47863628ae0ef263af6d4248db46d7c026f74c21f07db
  • python2-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.i686.rpm
    sha:88ca9330037f3a03472e7eff35d9aaae467f08c3e014cdb52a3dc81be99f923c
  • python2-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.x86_64.rpm
    sha:1afa753680ee76707ab1ed1250089efdcdd9ad1891d177d584d2ede566e30ed8
  • python3-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.aarch64.rpm
    sha:dd9a0308c8208c6753bdbc2d14d2e5a89a1610effb48f1cabe5a712d5695ecd4
  • python3-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.i686.rpm
    sha:dafe38c00e027328fa0c646fb9604cf5cf143fb9587ae4336ec52ffe0b29f7e8
  • python3-unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.x86_64.rpm
    sha:bf50d26d760bce5e91ee9f508b724b672bce1bb6b762748d8154d5caac95b4e7
  • unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.aarch64.rpm
    sha:54a7166829076a352b36f68de5aa39fce537832b39c49f50cbbb5eef824d851a
  • unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.i686.rpm
    sha:6bd84a55cc4efaf8252ce2b37fbaabf19496c37f379fd395aa50fc95c0c007ea
  • unbound-1.7.3-15.amzn2.0.17.tuxcare.els1.x86_64.rpm
    sha:70fa6e917d3ffa869abc95d7be3f59ef3a29ac069a039e9d6b3d01175fd48935
  • unbound-devel-1.7.3-15.amzn2.0.17.tuxcare.els1.aarch64.rpm
    sha:47954109fca89fac403512d60575b98316f1818304fb3761afeb969edb5c4eb9
  • unbound-devel-1.7.3-15.amzn2.0.17.tuxcare.els1.i686.rpm
    sha:363de029c6811cb10aba396b45f880c4ec8d91a1d61cfe91eea0dee596ba27e7
  • unbound-devel-1.7.3-15.amzn2.0.17.tuxcare.els1.x86_64.rpm
    sha:065b1c467120ea86bcf4e69a592ffb29a2fd853a712506e7d3d86e841b127705
  • unbound-libs-1.7.3-15.amzn2.0.17.tuxcare.els1.aarch64.rpm
    sha:69e0a1d96859456a5e1090e37281bf9388bc66f141f8904bb1a867189d5921cf
  • unbound-libs-1.7.3-15.amzn2.0.17.tuxcare.els1.i686.rpm
    sha:28571534110cad6de89e247ec6ba6e657d8cb01ade6fcbe10f47f15b1e3b55ea
  • unbound-libs-1.7.3-15.amzn2.0.17.tuxcare.els1.x86_64.rpm
    sha:928e441a667d77f83497c86581bd347917e57375db3e74083e1a2799b2aa811b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.