SB2026090461 - Anolis OS update for unbound



SB2026090461 - Anolis OS update for unbound

Published: September 4, 2026

Security Bulletin ID SB2026090461
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-44690)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to poison the DNS cache and cause DNS responses for arbitrary sibling zones to be treated as insecure.

The vulnerability exists due to improper input validation in aggressive NSEC processing when processing malicious DNS responses containing fraudulent wildcard DS records and invalid RRSIG labels. A remote attacker can control a single delegated zone and serve crafted DNS responses to poison the DNS cache and cause DNS responses for arbitrary sibling zones to be treated as insecure.

Exploitation requires Unbound to be configured with aggressive-nsec and the attacker to control one registered domain under an NSEC-signed parent domain.


Remediation

Install update from vendor's website.