[CLSA-2026:1790170355] unbound: Fix of 3 CVEs
Type:
security
Severity:
None
Release date:
2026-09-23 13:32:43 UTC
Description:
- rebase onto Amazon Linux 2 1.7.3-15.amzn2.0.16 (fix-buffer-overflow.patch); take the vendor's copy of CVE-2026-33278.patch, and renumber the TuxCare patches to Patch1020/Patch1021, since the vendor's new patch took Patch1019 - keep the TuxCare CVE-2019-16866 and CVE-2026-50252 backports - CVE-2026-33278: keep the NSEC3 parameter consistency check (param_set_same) as a separate patch. AL2's own CVE-2026-33278.patch carries only the services/cache/dns.c half of upstream 6a31e470; the validator/val_nsec3.c half, which rejects proofs mixing records from distinct NSEC3 chains, is not in it and is carried here instead
Updated packages:
  • python2-unbound-1.7.3-15.amzn2.0.16.tuxcare.els1.x86_64.rpm
    sha:d00e30b0106e5e68ff01bf089a284d88769a2b0f1a25e5a772bfd6c237e9ea77
  • python3-unbound-1.7.3-15.amzn2.0.16.tuxcare.els1.x86_64.rpm
    sha:6a533adba4364a21e2d70f664558616fc9892b4086bb40752c35fd18e5efef29
  • unbound-1.7.3-15.amzn2.0.16.tuxcare.els1.x86_64.rpm
    sha:76e012a4f56ec5efc6ba7c2c1fbce0c316e28e11f984318c534d7e55d2cb1a00
  • unbound-devel-1.7.3-15.amzn2.0.16.tuxcare.els1.x86_64.rpm
    sha:45f35e7632e0af0abd92f2468bce71046d5b8b97783b7f14c24d8968228ee5c5
  • unbound-libs-1.7.3-15.amzn2.0.16.tuxcare.els1.i686.rpm
    sha:f2d9697e09e86ecca3485a9bcf430c20647999d0bed26ffbd707c5f7aaeccc55
  • unbound-libs-1.7.3-15.amzn2.0.16.tuxcare.els1.x86_64.rpm
    sha:c79e77152defe1467f6c1033ce94d57412bbbbd0741d7833d5729f4d74a1f671
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.