Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12244

Опубликовано: 25 июн. 2026
Источник: debian
EPSS Низкий

Описание

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nsdfixed4.14.3-1package
nsdnot-affectedtrixiepackage
nsdnot-affectedbookwormpackage
nsdnot-affectedbullseyepackage

Примечания

  • https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt

EPSS

Процентиль: 25%
0.00325
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8
redhat
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
nvd
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
github
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

suse-cvrf
21 день назад

Security update for nsd

EPSS

Процентиль: 25%
0.00325
Низкий