Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12244

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:*
Версия от 4.14.0 (включая) до 4.14.3 (исключая)

EPSS

Процентиль: 25%
0.00325
Низкий

8.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8
redhat
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
debian
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone ...

CVSS3: 8.8
github
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

suse-cvrf
21 день назад

Security update for nsd

EPSS

Процентиль: 25%
0.00325
Низкий

8.8 High

CVSS3

Дефекты

CWE-122