Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-33278 — unbound: Unbound DNSSEC Validator Use-After-Free via Deep Copy Pointer Overwrite Leading to DoS and Possible Remote Code Execution CVE-2026-42944 — unbound: Heap overflow and crash with multiple nsid, cookie, padding EDNS options CVE-2026-42959 — unbound: Unbound DNSSEC Validator Denial of Service via Incorrect Write Offset Counter in Chase-Reply Messages CVE-2026-44608 — unbound: Unbound: Denial of Service due to locking inconsistency during RPZ XFR reload
🎯 Affected products5
- Red Hat Hardened Images
- unbound-main@aarch64 as a component of Red Hat Hardened Images
- unbound-main@noarch as a component of Red Hat Hardened Images
- unbound-main@src as a component of Red Hat Hardened Images
- unbound-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, avoid using `rpz-nsip` or `rpz-nsdname` triggers within Response Policy Zones (RPZ) that are configured for zone transfer (XFR) reloads. Alternatively, configure Unbound to use local RPZ files instead of XFR for these zones, as local RPZ files do not trigger the vulnerability. A restart of the Unbound service may be required for configuration changes to take effect, which could temporarily interrupt DNS resolution.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:19752
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-42959
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-33278
- externalhttps://access.redhat.com/security/cve/CVE-2026-42944
- externalhttps://access.redhat.com/security/cve/CVE-2026-44608
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_19752.json