Validating, recursive, and caching DNS(SEC) resolver
Go to file
RHEL Packaging Agent 3d77196b51 Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning
Backport fix for CVE-2026-44690 (cross-zone wildcard cache
poisoning via RRSIG.labels manipulation) from upstream commit
f7637a4f1 to unbound-1.16.2. The patch adds validation that
the wildcard canonical parent is within the RRSIG signer's
authority before caching, checks that the RRSIG label count
is not lower than the signer name's label count, and postpones
the wildcard cache update until after the NSEC/NSEC3 proof
succeeds.

CVE: CVE-2026-44690
Upstream patches:
 - f7637a4f18.patch
Resolves: RHEL-212801

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-05 12:28:24 +02:00
.fmf Import test plans from c9s 2026-04-30 10:36:00 +02:00
.gitignore Auto sync2gitlab import of unbound-1.16.2-2.el8.src.rpm 2022-08-11 18:17:33 +00:00
block-example.com.conf Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
ci.fmf Import test plans from c9s 2026-04-30 10:36:00 +02:00
example.com.conf Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
example.com.key Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
gating.yaml Import test plans from c9s 2026-04-30 10:36:00 +02:00
icannbundle.pem Auto sync2gitlab import of unbound-1.16.0-2.el8.src.rpm 2022-07-22 10:16:49 +00:00
plans.fmf Import test plans from c9s 2026-04-30 10:36:00 +02:00
remote-control.conf Ensure group access correction reaches also updated configs 2024-04-17 13:57:57 +02:00
root.anchor Add new DNSSEC root anchor 38696 2026-04-24 11:26:18 +02:00
root.key Add new DNSSEC root anchor 38696 2026-04-24 11:26:18 +02:00
sources Auto sync2gitlab import of unbound-1.16.2-2.el8.src.rpm 2022-08-11 18:17:33 +00:00
tmpfiles-unbound.conf Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound_munin_ Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound-1.15-source-compat.patch Auto sync2gitlab import of unbound-1.16.0-2.el8.src.rpm 2022-07-22 10:16:49 +00:00
unbound-1.15-soversion2-compat.patch Auto sync2gitlab import of unbound-1.16.2-2.el8.src.rpm 2022-08-11 18:17:33 +00:00
unbound-1.16-CVE-2022-3204.patch Auto sync2gitlab import of unbound-1.16.2-5.el8.src.rpm 2023-01-25 08:10:10 +00:00
unbound-1.16-CVE-2023-50387-CVE-2023-50868.patch Fix KeyTrap - Extreme CPU consumption in DNSSEC validator CVE-2023-50387 2024-04-17 13:53:26 +02:00
unbound-1.16.2.tar.gz.asc Auto sync2gitlab import of unbound-1.16.2-2.el8.src.rpm 2022-08-11 18:17:33 +00:00
unbound-1.20-unbound-anchor-key-38696.patch Update unbound-anchor built-in dnssec key 2026-04-24 11:29:01 +02:00
unbound-1.21-CVE-2024-8508.patch Fix CVE-2024-8508 2024-12-06 23:13:49 +01:00
unbound-1.23.1-CVE-2025-5994.patch Fix RebirthDay Attack (CVE-2025-5994) 2025-07-24 13:40:27 +02:00
unbound-1.25.1-CVE-2026-40622-test.patch Add upstream test for CVE-2026-40622 2026-06-24 11:37:38 +02:00
unbound-1.25.1-CVE-2026-40622.patch Fix CVE-2026-40622 and CVE-2026-44390 2026-06-23 17:49:03 +02:00
unbound-1.25.1-CVE-2026-41292.patch Fix CVE-2026-41292: DoS via excessive EDNS options 2026-06-24 11:39:42 +02:00
unbound-1.25.1-CVE-2026-42534.patch Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance 2026-06-24 11:54:42 +02:00
unbound-1.25.1-CVE-2026-42944.patch Fix CVE-2026-42944 2026-05-27 12:29:05 +02:00
unbound-1.25.1-CVE-2026-42959.patch Fix CVE-2026-42959 2026-05-27 12:29:07 +02:00
unbound-1.25.1-CVE-2026-44390.patch Fix CVE-2026-40622 and CVE-2026-44390 2026-06-23 17:49:03 +02:00
unbound-1.25.2-CVE-2026-44690.patch Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning 2026-08-05 12:28:24 +02:00
unbound-anchor.service Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound-anchor.timer Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound-keygen.service Auto sync2gitlab import of unbound-1.16.0-2.el8.src.rpm 2022-07-22 10:16:49 +00:00
unbound-munin.README Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound.conf Ensure group access correction reaches also updated configs 2024-04-17 13:57:57 +02:00
unbound.munin Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound.service Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00
unbound.spec Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning 2026-08-05 12:28:24 +02:00
unbound.sysconfig Auto sync2gitlab import of unbound-1.7.3-17.el8.src.rpm 2022-05-26 15:44:00 -04:00