rpm package
opensuse/nsd&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/nsd&distro=openSUSE%20Leap%2016.0
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-12490 | Hig | 7.5 | < 4.14.3-bp160.1.1 | 4.14.3-bp160.1.1 | Jun 25, 2026 | When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over T | |
| CVE-2026-12246 | Hig | 8.1 | < 4.14.3-bp160.1.1 | 4.14.3-bp160.1.1 | Jun 25, 2026 | NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes. | |
| CVE-2026-12245 | Hig | 7.5 | < 4.14.3-bp160.1.1 | 4.14.3-bp160.1.1 | Jun 25, 2026 | NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response. | |
| CVE-2026-12244 | Hig | 8.8 | < 4.14.3-bp160.1.1 | 4.14.3-bp160.1.1 | Jun 25, 2026 | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because |
- affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over T
- affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
- affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
- affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because