Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p22w-wq6p-g85g

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

EPSS

Процентиль: 25%
0.00325
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8
redhat
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
nvd
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
debian
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone ...

suse-cvrf
21 день назад

Security update for nsd

EPSS

Процентиль: 25%
0.00325
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-122