elsa-2026-36320

oracle_linux
Description

[1.24.2-15] - Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance [1.24.2-14] - Fix CVE-2026-41292: DoS via excessive EDNS options [1.24.2-13] - Add upstream unit test for CVE-2026-40622 [1.24.2-12] - Fix CVE-2026-44390: DoS with large RRsets [1.24.2-11] - Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack [1.24.2-10] - Fix CVE-2026-42959 [1.24.2-9] - Fix CVE-2026-42944 [1.24.2-8] - Fix CVE-2026-33278

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-40622",
    "CVE-2026-41292",
    "CVE-2026-42534",
    "CVE-2026-44390"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1.24.2-15]\n- Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance\n\n[1.24.2-14]\n- Fix CVE-2026-41292: DoS via excessive EDNS options\n\n[1.24.2-13]\n- Add upstream unit test for CVE-2026-40622\n\n[1.24.2-12]\n- Fix CVE-2026-44390: DoS with large RRsets\n\n[1.24.2-11]\n- Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack\n\n[1.24.2-10]\n- Fix CVE-2026-42959\n\n[1.24.2-9]\n- Fix CVE-2026-42944\n\n[1.24.2-8]\n- Fix CVE-2026-33278",
  "id": "ELSA-2026-36320",
  "ovalId": "oval:com.oracle.elsa:def:202636320",
  "source": "oracle_linux",
  "title": "ELSA-2026-36320:  unbound security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-36320.html"
}
View JSON API Download JSON