elsa-2026-36320
oracle_linux
Description
[1.24.2-15] - Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance [1.24.2-14] - Fix CVE-2026-41292: DoS via excessive EDNS options [1.24.2-13] - Add upstream unit test for CVE-2026-40622 [1.24.2-12] - Fix CVE-2026-44390: DoS with large RRsets [1.24.2-11] - Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack [1.24.2-10] - Fix CVE-2026-42959 [1.24.2-9] - Fix CVE-2026-42944 [1.24.2-8] - Fix CVE-2026-33278
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-40622",
"CVE-2026-41292",
"CVE-2026-42534",
"CVE-2026-44390"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1.24.2-15]\n- Fix CVE-2026-42534: Jostle logic bypass degrades resolution performance\n\n[1.24.2-14]\n- Fix CVE-2026-41292: DoS via excessive EDNS options\n\n[1.24.2-13]\n- Add upstream unit test for CVE-2026-40622\n\n[1.24.2-12]\n- Fix CVE-2026-44390: DoS with large RRsets\n\n[1.24.2-11]\n- Fix CVE-2026-40622: cache manipulation via 'ghost domain names' attack\n\n[1.24.2-10]\n- Fix CVE-2026-42959\n\n[1.24.2-9]\n- Fix CVE-2026-42944\n\n[1.24.2-8]\n- Fix CVE-2026-33278",
"id": "ELSA-2026-36320",
"ovalId": "oval:com.oracle.elsa:def:202636320",
"source": "oracle_linux",
"title": "ELSA-2026-36320: unbound security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-36320.html"
}