{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: Possible remote code execution during DNSSEC validation\n     - debian/patches/CVE-2026-33278.patch: Possible remote code execution during DNSSEC validation\n     - CVE-2026-33278\n   * SECURITY UPDATE: Ghost domain name variant\n     - debian/patches/CVE-2026-40622.patch: Ghost domain name variant\n     - CVE-2026-40622\n   * SECURITY UPDATE: Parsing a long list of incoming EDNS options degrades performance\n     - debian/patches/CVE-2026-41292.patch: Parsing a long list of incoming EDNS options degrades performance\n     - CVE-2026-41292\n   * SECURITY UPDATE: Crash during DNSSEC validation of malicious content\n     - debian/patches/CVE-2026-42959.patch: Crash during DNSSEC validation of malicious content\n     - CVE-2026-42959\n   * SECURITY UPDATE: Possible cache poisoning attack while following delegation\n     - debian/patches/CVE-2026-42960.patch: Possible cache poisoning attack while following delegation\n     - CVE-2026-42960\n   * SECURITY UPDATE: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined\n     - debian/patches/CVE-2026-56444.patch: Degradation of resolution service when discard-timeout and serve-expired-client-timeout are combined\n     - CVE-2026-56444",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/advisories/2026/clsa-2026_1789042546.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-10T12:17:14Z",
      "generator": {
        "date": "2026-09-10T12:17:14Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789042546",
      "initial_release_date": "2026-09-10T12:17:14Z",
      "revision_history": [
        {
          "date": "2026-09-10T12:17:14Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix of 6 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/python3-unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound-dev@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound8@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-host@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                "product": {
                  "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_id": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-anchor@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/python3-unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound-dev@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound8@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-host@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                "product": {
                  "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_id": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-anchor@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/python3-unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound-dev@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libunbound8@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-host@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                "product": {
                  "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_id": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/unbound-anchor@1.13.1-1%2Bdeb11u7%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64"
        },
        "product_reference": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64"
        },
        "product_reference": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel as a component of Debian 11",
          "product_id": "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        },
        "product_reference": "unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-56444",
      "cwe": {
        "id": "CWE-772",
        "name": "Missing Release of Resource after Effective Lifetime"
      },
      "notes": [
        {
          "category": "description",
          "text": "In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-56444"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56444.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-56444.txt"
        }
      ],
      "release_date": "2026-07-22T14:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-40622",
      "cwe": {
        "id": "CWE-346",
        "name": "Origin Validation Error"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-40622"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-40622.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-40622.txt"
        }
      ],
      "release_date": "2026-05-20T10:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-33278",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-33278"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19752",
          "url": "https://access.redhat.com/errata/RHSA-2026:19752"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:23231",
          "url": "https://access.redhat.com/errata/RHSA-2026:23231"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:24369",
          "url": "https://access.redhat.com/errata/RHSA-2026:24369"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-33278",
          "url": "https://access.redhat.com/security/cve/CVE-2026-33278"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2479808",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479808"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33278.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33278.json"
        }
      ],
      "release_date": "2026-05-20T10:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-42960",
      "cwe": {
        "id": "CWE-349",
        "name": "Acceptance of Extraneous Untrusted Data With Trusted Data"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-42960"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt"
        }
      ],
      "release_date": "2026-05-20T10:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-42959",
      "cwe": {
        "id": "CWE-824",
        "name": "Access of Uninitialized Pointer"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority filtering could decrease the AUTHORITY section count and create an uninitialized array slot. Combining these two, the validator later dereferences this uninitialized pointer, causing an immediate process crash. An adversary controlling a DNSSEC-signed domain can trigger this bug with a single query by configuring a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records. Unbound 1.25.1 contains a patch with a fix to use the proper counters to calculate the write offsets.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-42959"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42959.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42959.txt"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19752",
          "url": "https://access.redhat.com/errata/RHSA-2026:19752"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:23231",
          "url": "https://access.redhat.com/errata/RHSA-2026:23231"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:24365",
          "url": "https://access.redhat.com/errata/RHSA-2026:24365"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:24369",
          "url": "https://access.redhat.com/errata/RHSA-2026:24369"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-42959",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42959"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2479806",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2479806"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42959.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42959.json"
        }
      ],
      "release_date": "2026-05-20T10:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-41292",
      "cwe": {
        "id": "CWE-407",
        "name": "Inefficient Algorithmic Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
          "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-41292"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.txt"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:24013",
          "url": "https://access.redhat.com/errata/RHSA-2026:24013"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:36320",
          "url": "https://access.redhat.com/errata/RHSA-2026:36320"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:36777",
          "url": "https://access.redhat.com/errata/RHSA-2026:36777"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:37282",
          "url": "https://access.redhat.com/errata/RHSA-2026:37282"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:54769",
          "url": "https://access.redhat.com/errata/RHSA-2026:54769"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-41292",
          "url": "https://access.redhat.com/security/cve/CVE-2026-41292"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2480125",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480125"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41292.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41292.json"
        }
      ],
      "release_date": "2026-05-20T10:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-10T12:15:48.529062Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546",
          "product_ids": [
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound-dev-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:libunbound8-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:python3-unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-anchor-0:1.13.1-1+deb11u7+tuxcare.els2.armel",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.amd64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.arm64",
            "Debian-11:unbound-host-0:1.13.1-1+deb11u7+tuxcare.els2.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789042546"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}