Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-77860 — unbound: Unbound: Denial of Service via 'serve-expired' code path bypass CVE-2026-77955 — unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution CVE-2026-78227 — unbound: Unbound: Denial of Service via use-after-free in DoQ stream output buffer CVE-2026-80225 — unbound: Unbound: Denial of Service via continuous queries on TCP/DoT connection CVE-2026-81634 — unbound: Unbound: Heap buffer overflow via malicious DNSSEC response CVE-2026-81642 — unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY CVE-2026-82717 — unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis CVE-2026-82720 — unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup CVE-2026-85501 — unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
🎯 Affected products18
- Red Hat Hardened Images
- python3-unbound-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3-unbound-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-0:1.26.1-1.hum1@src as a component of Red Hat Hardened Images
- unbound-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-anchor-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-anchor-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-devel-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-devel-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-dracut-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-dracut-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-libs-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-libs-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
- unbound-munin-0:1.26.1-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- unbound-munin-0:1.26.1-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- unbound-utils-0:1.26.1-1.hum1@aarch64 as a component of Red Hat Hardened Images
- unbound-utils-0:1.26.1-1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, disable the 'serve-expired' option in the Unbound configuration. This can be achieved by setting 'serve-expired: no' in the 'unbound.conf' file. A restart of the Unbound service is required for the changes to take effect. Disabling this feature may impact the availability of stale DNS records. Workaround: To mitigate this issue, avoid configuring Unbound with `zonemd-check: yes` for zones located below a trust anchor, especially when the `zonefile` option is also enabled. If ZONEMD is required, ensure that zones are not configured in a way that allows for this asynchronous resolution vulnerability. Disabling the `zonemd-check` option or removing the `zonefile` option for affected zones can prevent the attack window. A restart of the Unbound service is required for configuration changes to take effect. Workaround: To mitigate this do not set quic-port unless DNS-over-QUIC is required. If it is enabled, allow it only from trusted clients. Workaround: To mitigate this issue, restrict network access to the Unbound DNS resolver to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Unbound service ports (e.g., TCP port 53 for DNS over TCP, TCP port 853 for DNS over TLS). For example, using `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="53" protocol="tcp" accept'` and `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_NETWORK>" port port="853" protocol="tcp" accept'`. After adding rules, apply them with `firewall-cmd --reload`. Replace `<TRUSTED_NETWORK>` with the IP address or network range of trusted clients. Reloading firewall rules may temporarily interrupt network connections. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this restrict Unbound to trusted clients and limit which upstream name servers it can query. If Unbound is unused, disable or remove the service. Apply process/cgroup limits to contain crash impact. Workaround: To mitigate this issue, disable DNS-over-HTTPS (DoH) support in Unbound if it is not required. This can typically be achieved by commenting out or removing the `do-https:` configuration block in the `unbound.conf` file and restarting the Unbound service. Disabling DoH may affect clients relying on this protocol for DNS resolution. A service restart is required for the changes to take effect. Workaround: To mitigate implement hard caps on iterative processing loops and resource allocations per request. Apply rate limiting and set strict connection/processing timeouts to prevent a single complex operation from tying up worker threads. For this specific flaw, administrators can also configure system-level resource constraints (like CPU cgroups) for the service.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:68590
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-81642
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-82720
- externalhttps://access.redhat.com/security/cve/CVE-2026-81634
- externalhttps://access.redhat.com/security/cve/CVE-2026-80225
- externalhttps://access.redhat.com/security/cve/CVE-2026-77860
- externalhttps://access.redhat.com/security/cve/CVE-2026-77955
- externalhttps://access.redhat.com/security/cve/CVE-2026-85501
- externalhttps://access.redhat.com/security/cve/CVE-2026-82717
- externalhttps://access.redhat.com/security/cve/CVE-2026-78227
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68590.json