{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2022/cve-2022-30699-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-04-24T13:01:27Z",
      "generator": {
        "date": "2026-04-24T13:01:27Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2022-30699-ELS_OS-RHEL7ELS",
      "initial_release_date": "2022-08-01T15:15:00Z",
      "revision_history": [
        {
          "date": "2022-08-01T15:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-20T09:24:03Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-04-24T13:01:27Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2022-30699"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "unbound-0:1.6.6-5.el7_8.x86_64",
                "product": {
                  "name": "unbound-0:1.6.6-5.el7_8.x86_64",
                  "product_id": "unbound-0:1.6.6-5.el7_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound@1.6.6-5.el7_8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.x86_64",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.x86_64",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound-libs@1.6.6-5.el7_8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.x86_64",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.x86_64",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound-devel@1.6.6-5.el7_8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-python-0:1.6.6-5.el7_8.x86_64",
                "product": {
                  "name": "unbound-python-0:1.6.6-5.el7_8.x86_64",
                  "product_id": "unbound-python-0:1.6.6-5.el7_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound-python@1.6.6-5.el7_8?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.i686",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.i686",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound-libs@1.6.6-5.el7_8?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.i686",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.i686",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/unbound-devel@1.6.6-5.el7_8?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                "product": {
                  "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_id": "unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound@1.6.6-5.el7_8.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                "product": {
                  "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_id": "unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound@1.6.6-5.el7_8.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-libs@1.6.6-5.el7_8.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-libs@1.6.6-5.el7_8.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-devel@1.6.6-5.el7_8.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-devel@1.6.6-5.el7_8.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                "product": {
                  "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_id": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-python@1.6.6-5.el7_8.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                "product": {
                  "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_id": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-python@1.6.6-5.el7_8.tuxcare.els3?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-libs@1.6.6-5.el7_8.tuxcare.els3?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                "product": {
                  "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                  "product_id": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-libs@1.6.6-5.el7_8.tuxcare.els4?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-devel@1.6.6-5.el7_8.tuxcare.els3?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                "product": {
                  "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                  "product_id": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/unbound-devel@1.6.6-5.el7_8.tuxcare.els4?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64"
        },
        "product_reference": "unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64"
        },
        "product_reference": "unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64"
        },
        "product_reference": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64"
        },
        "product_reference": "unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.6.6-5.el7_8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-0:1.6.6-5.el7_8.x86_64"
        },
        "product_reference": "unbound-0:1.6.6-5.el7_8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.i686"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-libs-0:1.6.6-5.el7_8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.x86_64"
        },
        "product_reference": "unbound-libs-0:1.6.6-5.el7_8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.i686"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.6.6-5.el7_8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.x86_64"
        },
        "product_reference": "unbound-devel-0:1.6.6-5.el7_8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-python-0:1.6.6-5.el7_8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.x86_64"
        },
        "product_reference": "unbound-python-0:1.6.6-5.el7_8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2022-30699",
      "cwe": {
        "id": "CWE-613",
        "name": "Insufficient Session Expiration"
      },
      "notes": [
        {
          "category": "description",
          "text": "NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the \"ghost domain names\" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation information is expired. Upon receiving the delayed answer containing the delegation information, Unbound overwrites the now expired entries. This action can be repeated when the delegation information is about to expire making the rogue delegation information ever-updating. From version 1.16.2 on, Unbound stores the start time for a query and uses that to decide if the cached delegation information can be overwritten.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
          "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
          "Red-Hat-7:unbound-0:1.6.6-5.el7_8.x86_64",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.i686",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
          "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.x86_64",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.i686",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
          "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.x86_64",
          "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
          "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
          "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2022-30699"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00024.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5L3ZFWZZFPBIL654BG75RWXUMPFQJ5EC/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5L3ZFWZZFPBIL654BG75RWXUMPFQJ5EC/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D35CX4SCZVNKZTWJXPDFTHWZHINMGEZD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D35CX4SCZVNKZTWJXPDFTHWZHINMGEZD/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202212-02",
          "url": "https://security.gentoo.org/glsa/202212-02"
        },
        {
          "category": "external",
          "summary": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2022-30698_CVE-2022-30699.txt",
          "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2022-30698_CVE-2022-30699.txt"
        }
      ],
      "release_date": "2022-08-01T15:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "This issue only applies when Unbound is used as a full recursive resolver performing iterative lookups; forward-only configurations that send queries to specific upstream resolvers are not exposed to the rogue-authoritative timing trick this attack relies on. Exploitation requires the attacker to control the queried domain’s authoritative nameserver and precisely time delayed responses around TTL expiry to perpetually refresh that same delegation, which sustains reachability of the attacker’s own domain but does not enable arbitrary cache poisoning of unrelated domains, privilege escalation, or code execution. Given these narrow preconditions and the limited, domain-scoped impact, this CVE represents low operational risk in centrally managed server/VM environments and can be safely deprioritized.",
          "product_ids": [
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.i686",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-devel-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.i686",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-libs-0:1.6.6-5.el7_8.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els3.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.tuxcare.els4.x86_64",
            "Red-Hat-7:unbound-python-0:1.6.6-5.el7_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}