VYPR

rpm package

opensuse/nsd&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/nsd&distro=openSUSE%20Leap%2016.0

Vulnerabilities (4)

  • CVE-2026-12490HigJun 25, 2026
    affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1

    When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over T

  • CVE-2026-12246HigJun 25, 2026
    affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1

    NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

  • CVE-2026-12245HigJun 25, 2026
    affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1

    NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

  • CVE-2026-12244HigJun 25, 2026
    affected < 4.14.3-bp160.1.1fixed 4.14.3-bp160.1.1

    If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because