Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12244

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 8

Описание

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

A flaw was found in nsd. When nsd is configured as a secondary server for a zone, a remote attacker, acting as the primary server for that zone, can send a specially crafted DNS message within an AXFR (Asynchronous Full Zone Transfer) request. This message, containing a malformed SVCB (Service Binding) resource record, can cause a heap overflow, leading to arbitrary code execution. This vulnerability poses a significant risk, especially in multi-tenant secondary DNS deployments, due to the potential for a controlled write of a large amount of data.

Отчет

This Important vulnerability in NSD allows a remote attacker, acting as a configured primary DNS server, to trigger a heap overflow during an AXFR zone transfer. This can lead to arbitrary code execution on the secondary NSD server. The risk is particularly significant in multi-tenant environments where NSD serves as a secondary for multiple zones, as a compromised primary could exploit this flaw within NSD's trust boundary. This vulnerability doesn't affect any supported Red Hat Product.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2491587nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
nvd
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

CVSS3: 8.8
debian
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone ...

CVSS3: 8.8
github
около 2 месяцев назад

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

suse-cvrf
21 день назад

Security update for nsd

8 High

CVSS3