Bug 2316358
Summary: | CVE-2024-8508 unbound: Unbounded name compression could lead to Denial of Service [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Robb Gatica <rgatica> |
Component: | unbound | Assignee: | Petr Menšík <pemensik> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 40 | CC: | paul.wouters, pemensik, pj.pandit |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
URL: | https://nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt | ||
Whiteboard: | {"flaws": ["c331c51c-704c-45ee-91ac-41408f6d01c9"]} | ||
Fixed In Version: | unbound-1.21.1-3.fc40 unbound-1.21.1-1.fc41 unbound-1.21.1-3.fc39 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2024-10-06 02:11:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2316313 | ||
Bug Blocks: | 2316321 |
Description
Robb Gatica
2024-10-03 20:08:55 UTC
CVE details: https://nlnetlabs.nl/downloads/unbound/CVE-2024-8508.txt Fixed as rebase to unbound 1.21.1 FEDORA-2024-a5d6cd9f0a (unbound-1.21.1-1.fc41) has been submitted as an update to Fedora 41. https://bodhi.fedoraproject.org/updates/FEDORA-2024-a5d6cd9f0a FEDORA-2024-c07e065747 (unbound-1.21.1-3.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2024-c07e065747 FEDORA-2024-2ba00c906c (unbound-1.21.1-3.fc39) has been submitted as an update to Fedora 39. https://bodhi.fedoraproject.org/updates/FEDORA-2024-2ba00c906c FEDORA-2024-c07e065747 has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-c07e065747` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-c07e065747 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2024-2ba00c906c has been pushed to the Fedora 39 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-2ba00c906c` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-2ba00c906c See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2024-a5d6cd9f0a has been pushed to the Fedora 41 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-a5d6cd9f0a` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-a5d6cd9f0a See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2024-c07e065747 (unbound-1.21.1-3.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2024-a5d6cd9f0a (unbound-1.21.1-1.fc41) has been pushed to the Fedora 41 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2024-2ba00c906c (unbound-1.21.1-3.fc39) has been pushed to the Fedora 39 stable repository. If problem still persists, please make note of it in this bug report. |