Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0837 - Security Advisory
Issued:
2025-01-30
Updated:
2025-01-30

RHSA-2025:0837 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: unbound security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for unbound is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.

Security Fix(es):

  • unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation (CVE-2024-1488)
  • unbound: Unbounded name compression could lead to Denial of Service (CVE-2024-8508)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2264183 - CVE-2024-1488 unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation
  • BZ - 2316321 - CVE-2024-8508 unbound: Unbounded name compression could lead to Denial of Service

CVEs

  • CVE-2024-1488
  • CVE-2024-8508

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
unbound-1.16.2-5.8.el8_10.src.rpm SHA-256: 96ae66be46b26377e639c6a97d07b954b17ee0f185b68ab35f5ffbf6c9718fc0
x86_64
python3-unbound-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 488bd635a2a16cca6eb597691b5f59e2323be28620aee0ca7ef375ee5fdc14b9
python3-unbound-debuginfo-1.16.2-5.8.el8_10.i686.rpm SHA-256: b156c71b68b0c9f8b09026237289b21fb0382923d9f88d3fcba2792ccfb6fc93
python3-unbound-debuginfo-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 2c06121bad3d09a29b714eeee5ac9dcc0d7764f703a9e45c373e373fda5c1f1d
unbound-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: f8a88611d884bc291db38305609b04921f0a4d42544af63efec1f537d70f57ef
unbound-debuginfo-1.16.2-5.8.el8_10.i686.rpm SHA-256: 4db183b9ca441171b4014ebc30ea59004f662ed291165324b63f9f0dd8cbb4a8
unbound-debuginfo-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 246df7df8e91bae4738080b14d86ae0392acafd7a859fa8fa0ab81c4afe40f4c
unbound-debugsource-1.16.2-5.8.el8_10.i686.rpm SHA-256: de5129a71fdb7597c26d85901f81ffb5ac2517a8b03bec3f0a0f7bc8a126caa5
unbound-debugsource-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 69062041af23ad591da444f79c5a5c988cba4a7490bd7528d24edffb4eb09344
unbound-devel-1.16.2-5.8.el8_10.i686.rpm SHA-256: a9527664e46e3040f50dfba7bfc020a68305512747547ef0dcaa5b1a5d258e6b
unbound-devel-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 8c3ea2212458cbf049d0d339eca4736c5e75222be76b27b1f0aa3955dfa06383
unbound-libs-1.16.2-5.8.el8_10.i686.rpm SHA-256: 49366779442d627005febbb666a5e63a9de044fe56b5ef4af24ef487267fdf0f
unbound-libs-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: 77ddd674fa4e3a1f63bff42844b93f41711e4caf0939c92f2e92a79275ec6bd0
unbound-libs-debuginfo-1.16.2-5.8.el8_10.i686.rpm SHA-256: 079597f8ab9680e21be82965f329c243e9f3d3537581ec6cd78d115253c0dbaa
unbound-libs-debuginfo-1.16.2-5.8.el8_10.x86_64.rpm SHA-256: d85cb682af828116e3fbebbf76aba0173edc3c6948041fa2961d02ba2a1c553e

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
unbound-1.16.2-5.8.el8_10.src.rpm SHA-256: 96ae66be46b26377e639c6a97d07b954b17ee0f185b68ab35f5ffbf6c9718fc0
s390x
python3-unbound-1.16.2-5.8.el8_10.s390x.rpm SHA-256: fa0c59112268b822ebaf0c1a92527a210ee54c6629eada4979724367590fdb12
python3-unbound-debuginfo-1.16.2-5.8.el8_10.s390x.rpm SHA-256: c62878fb8427f1ee0b1a055e087b843116f8eaf3507d6194ee4ee929d9e7645c
unbound-1.16.2-5.8.el8_10.s390x.rpm SHA-256: 5bf30754b7c09b25612b3e4f607570461c241a3f4b8dc5e73eee69d69a0516b5
unbound-debuginfo-1.16.2-5.8.el8_10.s390x.rpm SHA-256: 6b1fd0a43ca0a38387fbb6955c0f69bcfd3c453c3d7917e41eadced0db25ff0c
unbound-debugsource-1.16.2-5.8.el8_10.s390x.rpm SHA-256: 9ce8dd66c9328df1e564ad3de910f84d05b88e011a9a6bfb2ae3a66717d5ff3c
unbound-devel-1.16.2-5.8.el8_10.s390x.rpm SHA-256: 3fdfb6c0eab44d5d9503d6e753a40ea123e85e0fd235d3fb229f2745450e9e10
unbound-libs-1.16.2-5.8.el8_10.s390x.rpm SHA-256: 12bbd0a21269eafd8e13fe7a354b08f9414d46eabb70fcc012dc19ea4538e7cd
unbound-libs-debuginfo-1.16.2-5.8.el8_10.s390x.rpm SHA-256: f492dc102ab9cd04815ab9e94f06a70ae5bdca6616dcfb375b3b9cf4b22cae0e

Red Hat Enterprise Linux for Power, little endian 8

SRPM
unbound-1.16.2-5.8.el8_10.src.rpm SHA-256: 96ae66be46b26377e639c6a97d07b954b17ee0f185b68ab35f5ffbf6c9718fc0
ppc64le
python3-unbound-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: 953550e8a7af28a7e5577beffbd54b5d6d46718f4db5942ce95b9661db2a534e
python3-unbound-debuginfo-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: 81cef42fd935e55eb1c9c2c2e26c9ece378748c7734f946823bf741bda5f625c
unbound-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: aecd04301815a52dd30360242e66e58cc1f62320f5c17ca1477299cbd3e37da2
unbound-debuginfo-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: 2ee9a65922539e4b5acfc537a914345d021585c6e4bc43e5d6b9479193ada79a
unbound-debugsource-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: f39cd1aa2538e0772d08752460e00f6e4f801d8e75eef5fec381804e818e2a3e
unbound-devel-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: f19854c711871b01cc5cd03d2a311087a5f1c2c9d41bbf9e1163dbdba9bebf0c
unbound-libs-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: 413963c7acdd0bfad2b4da079f3ff1739c2f7b50f144f39c3ae53194a35d3e09
unbound-libs-debuginfo-1.16.2-5.8.el8_10.ppc64le.rpm SHA-256: 6430c456e9bb8e64c92975f518c98cdd191269d607fa7e7139743efcd517d4d2

Red Hat Enterprise Linux for ARM 64 8

SRPM
unbound-1.16.2-5.8.el8_10.src.rpm SHA-256: 96ae66be46b26377e639c6a97d07b954b17ee0f185b68ab35f5ffbf6c9718fc0
aarch64
python3-unbound-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: 5f4e4508b3aac14408b4d6a4722e571f6beb8ad8096f64bad7719151e78af658
python3-unbound-debuginfo-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: 5aa77c8d4d2441f988cb17cb8767202e9c4f9b74cb1dbe3c4a239d88d0811a89
unbound-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: fe0c0c32559e8b465375d4fb75958d20c71b7b6731b4a1ed4fe6bd9340f92d5c
unbound-debuginfo-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: 1bf8386846f272a54561bd48f04bc5f1085004a3713e7a428b44691ae269436d
unbound-debugsource-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: b2d63f491cba2eac643bfcac4a62a51a8d2eaffc0eea8de9cd50592e66965798
unbound-devel-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: 93f0c9aee8a0600ed5cbb628458c2244b51579ec85f4bca671480c7ee8fc1cf3
unbound-libs-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: ec9e5d7154f173442c33603386ee2ae85ea5172fcab2c46d5874d82df28a94a0
unbound-libs-debuginfo-1.16.2-5.8.el8_10.aarch64.rpm SHA-256: 66381428b050edd3b70db114c8772e19fa4fd31900695398fe7ebed506b5f178

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility