RLSA-2021:1853
Dashboard / Vulnerabilities / RLSA-2021:1853
RLSA-2021:1853
Summary: Moderate: unbound security, bug fix, and enhancement update
Details: The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: integer overflow in the regional allocator via regional_alloc (CVE-2019-25032) * unbound: integer overflow in sldns_str2wire_dname_buf_origin can lead to an out-of-bounds write (CVE-2019-25034) * unbound: out-of-bounds write in sldns_bget_token_par (CVE-2019-25035) * unbound: assertion failure and denial of service in synth_cname (CVE-2019-25036) * unbound: assertion failure and denial of service in dname_pkt_copy via an invalid packet (CVE-2019-25037) * unbound: integer overflow in a size calculation in dnscrypt/dnscrypt.c (CVE-2019-25038) * unbound: integer overflow in a size calculation in respip/respip.c (CVE-2019-25039) * unbound: infinite loop via a compressed name in dname_pkt_copy (CVE-2019-25040) * unbound: assertion failure via a compressed name in dname_pkt_copy (CVE-2019-25041) * unbound: out-of-bounds write via a compressed name in rdata_copy (CVE-2019-25042) * unbound: symbolic link traversal when writing PID file (CVE-2020-28935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.
References: https://errata.rockylinux.org/RLSA-2021:1853, https://bugzilla.redhat.com/show_bug.cgi?id=1714175, https://bugzilla.redhat.com/show_bug.cgi?id=1842837, https://bugzilla.redhat.com/show_bug.cgi?id=1850460, https://bugzilla.redhat.com/show_bug.cgi?id=1878761, https://bugzilla.redhat.com/show_bug.cgi?id=1954772, https://bugzilla.redhat.com/show_bug.cgi?id=1954778, https://bugzilla.redhat.com/show_bug.cgi?id=1954780, https://bugzilla.redhat.com/show_bug.cgi?id=1954782, https://bugzilla.redhat.com/show_bug.cgi?id=1954794, https://bugzilla.redhat.com/show_bug.cgi?id=1954796, https://bugzilla.redhat.com/show_bug.cgi?id=1954797, https://bugzilla.redhat.com/show_bug.cgi?id=1954799, https://bugzilla.redhat.com/show_bug.cgi?id=1954801, https://bugzilla.redhat.com/show_bug.cgi?id=1954804
Affected packages
Package
Name: unbound
Purl: pkg:rpm/rocky-linux/unbound?distro=rocky-linux-8-4-legacy&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
