If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
This issue is fixed starting with version 4.14.3.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt |
|
History
Thu, 25 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes | |
| Title | Heap overflow and crash with crafted SVCB RR | |
| Weaknesses | CWE-122 CWE-190 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-06-25T12:45:34.403Z
Reserved: 2026-06-15T06:46:44.866Z
Link: CVE-2026-12244
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T07:30:17Z