Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: unbound: * python3-unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-anchor-1.25.1-1.hum1 (aarch64, x86_64) * unbound-devel-1.25.1-1.hum1 (aarch64, x86_64) * unbound-dracut-1.25.1-1.hum1 (aarch64, x86_64) * unbound-libs-1.25.1-1.hum1 (aarch64, x86_64) * unbound-munin-1.25.1-1.hum1 (noarch) * unbound-utils-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-32792 is a denial of service vulnerability in Unbound DNS resolver when compiled with DNSCrypt support. A remote attacker can send a crafted DNSCrypt query that causes Unbound to read beyond allocated memory, resulting in a heap overflow and service crash. The exploitation likelihood is low due to reliance on specific memory layouts and subsequent packet checks. This vulnerability affects Red Hat Hardened Images RPMs containing Unbound components. Red Hat has not provided a patch or effective mitigation at this time.
Potential Impact
Successful exploitation causes a denial of service by crashing the Unbound service. There is no impact on confidentiality or integrity. The attack requires network access but no privileges or user interaction. The likelihood of a crash is low due to internal checks and memory layout dependencies.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories for updates. Upgrading to a fixed version when available is recommended. Customers with Red Hat Technical Account Managers can seek direct guidance. No official fix has been released yet.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: unbound: * python3-unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-anchor-1.25.1-1.hum1 (aarch64, x86_64) * unbound-devel-1.25.1-1.hum1 (aarch64, x86_64) * unbound-dracut-1.25.1-1.hum1 (aarch64, x86_64) * unbound-libs-1.25.1-1.hum1 (aarch64, x86_64) * unbound-munin-1.25.1-1.hum1 (noarch) * unbound-utils-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-32792 is a denial of service vulnerability in Unbound DNS resolver when compiled with DNSCrypt support. A remote attacker can send a crafted DNSCrypt query that causes Unbound to read beyond allocated memory, resulting in a heap overflow and service crash. The exploitation likelihood is low due to reliance on specific memory layouts and subsequent packet checks. This vulnerability affects Red Hat Hardened Images RPMs containing Unbound components. Red Hat has not provided a patch or effective mitigation at this time.
Potential Impact
Successful exploitation causes a denial of service by crashing the Unbound service. There is no impact on confidentiality or integrity. The attack requires network access but no privileges or user interaction. The likelihood of a crash is low due to internal checks and memory layout dependencies.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories for updates. Upgrading to a fixed version when available is recommended. Customers with Red Hat Technical Account Managers can seek direct guidance. No official fix has been released yet.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:2281-1
- Cve Count
- 11
- Additional Cves
- ["CVE-2026-33278","CVE-2026-40622","CVE-2026-41292","CVE-2026-42534","CVE-2026-42923","CVE-2026-42944","CVE-2026-42959","CVE-2026-42960","CVE-2026-44390","CVE-2026-44608"]
- State
- PUBLISHED
Threat ID: 6a248d87e29bf47b50d6930d
Added to database: 06/06/2026, 21:13:43 UTC
Last enriched: 08/16/2026, 17:42:22 UTC
Last updated: 09/14/2026, 10:01:30 UTC
Views: 219
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.