Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Oracle Linux 10 Unbound Important DoS Threat Advisory ELSA-2026-36320

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Important security advisory for Oracle Linux 10 details updates for unbound, addressing key denial of service issues and related CVEs.
Oracle Linux has released updates for several unbound packages for version 10, addressing multiple CVEs related to performance degradation and denial-of-service vulnerabilities.

Summary

[1.24.2-15] - Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance [1.24.2-14] - Fix CVE-2026-41292: DoS via excessive EDNS options [1.24.2-13] - Add upstream unit test for CVE-2026-40622 [1.24.2-12] - Fix CVE-2026-44390: DoS with large RRsets [1.24.2-11] - Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack [1.24.2-10] - Fix CVE-2026-42959 [1.24.2-9] - Fix CVE-2026-42944 [1.24.2-8] - Fix CVE-2026-33278

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/unbound-1.24.2-7.el10_2.2.src.rpm

x86_64

python3-unbound-1.24.2-7.el10_2.2.x86_64.rpm unbound-1.24.2-7.el10_2.2.x86_64.rpm unbound-anchor-1.24.2-7.el10_2.2.x86_64.rpm unbound-devel-1.24.2-7.el10_2.2.x86_64.rpm unbound-dracut-1.24.2-7.el10_2.2.x86_64.rpm unbound-libs-1.24.2-7.el10_2.2.x86_64.rpm unbound-utils-1.24.2-7.el10_2.2.x86_64.rpm

aarch64

python3-unbound-1.24.2-7.el10_2.2.aarch64.rpm unbound-1.24.2-7.el10_2.2.aarch64.rpm unbound-anchor-1.24.2-7.el10_2.2.aarch64.rpm unbound-devel-1.24.2-7.el10_2.2.aarch64.rpm unbound-dracut-1.24.2-7.el10_2.2.aarch64.rpm unbound-libs-1.24.2-7.el10_2.2.aarch64.rpm unbound-utils-1.24.2-7.el10_2.2.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-40622 CVE-2026-41292 CVE-2026-42534 CVE-2026-44390

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.