Threats Tagged 'cve-2026-42534'
View all threats tagged with 'cve-2026-42534'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-42534'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities have been identified in the unbound DNS resolver packages used in Red Hat Enterprise Linux 8. These include denial of service issues caused by excessive EDNS options, large DNS resource record sets, and degraded resolution performance, as well as a cache manipulation vulnerability via a 'ghost domain names' attack. Red Hat has issued an important security advisory with updates addressing these issues. Join the discussion | GCVE Database | 07/09/2026, 13:00:54 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Multiple security vulnerabilities have been identified in the unbound DNS resolver packages used in Red Hat Enterprise Linux 9. These include denial of service issues caused by excessive EDNS options, large DNS resource record sets, and degraded resolution performance, as well as a cache manipulation vulnerability via 'ghost domain names'. Red Hat has released security updates addressing these issues. Join the discussion | GCVE Database | 07/08/2026, 16:36:29 UTC Added: 08/21/2026, 14:22:11 UTC |
0 Multiple security vulnerabilities affecting the unbound DNS resolver in Red Hat Enterprise Linux 10 have been addressed. These include denial of service issues caused by excessive EDNS options, large DNS resource record sets, and degraded resolution performance, as well as a cache manipulation vulnerability via 'ghost domain names'. The vulnerabilities have been rated with a security impact of Important by Red Hat Product Security. Updates are available to remediate these issues in Red Hat Enterprise Linux 10 and related CodeReady Linux Builder products across multiple architectures. Join the discussion | GCVE Database | 07/07/2026, 16:24:30 UTC Added: 08/21/2026, 14:22:11 UTC |
0 This update includes the following RPMs: unbound: * python3-unbound-1.25.1-2.hum1 (aarch64, x86_64) * unbound-1.25.1-2.hum1 (aarch64, x86_64) * unbound-anchor-1.25.1-2.hum1 (aarch64, x86_64) * unbound-devel-1.25.1-2.hum1 (aarch64, x86_64) * unbound-dracut-1.25.1-2.hum1 (aarch64, x86_64) * unbound-libs-1.25.1-2.hum1 (aarch64, x86_64) * unbound-munin-1.25.1-2.hum1 (noarch) * unbound-utils-1.25.1-2.hum1 (aarch64, x86_64) * unbound-1.25.1-2.hum1.src (src) Join the discussion | GCVE Database | 06/07/2026, 01:10:52 UTC Added: 07/19/2026, 03:41:43 UTC |
0 This update includes the following RPMs: unbound: * python3-unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1 (aarch64, x86_64) * unbound-anchor-1.25.1-1.hum1 (aarch64, x86_64) * unbound-devel-1.25.1-1.hum1 (aarch64, x86_64) * unbound-dracut-1.25.1-1.hum1 (aarch64, x86_64) * unbound-libs-1.25.1-1.hum1 (aarch64, x86_64) * unbound-munin-1.25.1-1.hum1 (noarch) * unbound-utils-1.25.1-1.hum1 (aarch64, x86_64) * unbound-1.25.1-1.hum1.src (src) Join the discussion | GCVE Database | 05/23/2026, 20:39:46 UTC Added: 06/06/2026, 21:13:43 UTC |
NLnet Labs Unbound versions up to and including 1.25.0 contain a vulnerability in the jostle logic that can degrade DNS resolution performance. This occurs because retransmitted duplicate queries renew the age of slow queries, preventing their replacement and causing performance degradation. An attacker controlling a slow or malicious authoritative DNS server can exploit this to degrade resolution performance or cause denial of resolution service. Cache and local data responses are unaffected. The issue is fixed in Unbound version 1.25.1, which attaches an immutable start time to queries to enable correct aging and replacement logic. Join the discussion | GCVE Database | 05/20/2026, 09:19:37 UTC Added: 07/30/2026, 05:47:05 UTC |
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended. Join the discussion | CVE Database V5 | 05/20/2026, 09:19:37 UTC Added: 05/20/2026, 10:03:41 UTC |
Showing 1 to 7 of 7 results