Fedora Account System
Red Hat Associate
Red Hat Customer
An attacker's zone can respond with an RRSIG with fewer labels than the zone it's in, causing named to produce a wildcard name shorter than the attacker's zone — resulting in cache poisoning. Requires synth-from-dnssec yes (which IS the default).
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54509 https://access.redhat.com/errata/RHSA-2026:54509
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54510 https://access.redhat.com/errata/RHSA-2026:54510
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54654 https://access.redhat.com/errata/RHSA-2026:54654
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:55441 https://access.redhat.com/errata/RHSA-2026:55441
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55437 https://access.redhat.com/errata/RHSA-2026:55437
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55442 https://access.redhat.com/errata/RHSA-2026:55442
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:57189 https://access.redhat.com/errata/RHSA-2026:57189
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:57362 https://access.redhat.com/errata/RHSA-2026:57362
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:60383 https://access.redhat.com/errata/RHSA-2026:60383