{
  "cves": [
    "CVE-2026-40622",
    "CVE-2026-41292",
    "CVE-2026-42534",
    "CVE-2026-44390"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1.24.2-15]\n- Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance\n\n[1.24.2-14]\n- Fix CVE-2026-41292: DoS via excessive EDNS options\n\n[1.24.2-13]\n- Add upstream unit test for CVE-2026-40622\n\n[1.24.2-12]\n- Fix CVE-2026-44390: DoS with large RRsets\n\n[1.24.2-11]\n- Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack\n\n[1.24.2-10]\n- Fix CVE-2026-42959\n\n[1.24.2-9]\n- Fix CVE-2026-42944\n\n[1.24.2-8]\n- Fix CVE-2026-33278",
  "id": "ELSA-2026-36320",
  "ovalId": "oval:com.oracle.elsa:def:202636320",
  "source": "oracle_linux",
  "title": "ELSA-2026-36320:  unbound security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-36320.html"
}