Fedora Account System
Red Hat Associate
Red Hat Customer
The resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. An attacker controlling ANY DNSSEC-signed zone can craft NSEC records spanning into victim zones, enabling cross-zone cache poisoning with AD=1 (Authenticated Data flag set)
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54509 https://access.redhat.com/errata/RHSA-2026:54509
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54510 https://access.redhat.com/errata/RHSA-2026:54510
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54654 https://access.redhat.com/errata/RHSA-2026:54654
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:55441 https://access.redhat.com/errata/RHSA-2026:55441
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55437 https://access.redhat.com/errata/RHSA-2026:55437
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55442 https://access.redhat.com/errata/RHSA-2026:55442
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:57189 https://access.redhat.com/errata/RHSA-2026:57189
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:57362 https://access.redhat.com/errata/RHSA-2026:57362
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:60383 https://access.redhat.com/errata/RHSA-2026:60383