Bug 2535057 (CVE-2026-85501)
| Summary: | CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Unbound. This vulnerability, termed 'ReTrap', allows a remote attacker to launch algorithmic complexity attacks on the Domain Name System Security Extensions (DNSSEC) validation process. By serving malicious zones or responses, an attacker can exploit various mechanisms, such as mismatched DNSKEY records, deeply nested domains, or excessive invalid NSEC records. Successful exploitation leads to a degradation of service, effectively causing a Denial of Service (DoS) for affected Unbound resolvers.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2537353 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-16 09:06:52 UTC
|