7.2 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
20 packages
- pdnsd
- dnsdbq
- nsdiff
- dnsdiag
- dnsdist
- zeronsd
- adidnsdump
- perlPackages.nsdiff
- perl5Packages.nsdiff
- perl538Packages.nsdiff
- perl540Packages.nsdiff
- idrisPackages.transducers
- python312Packages.webexpythonsdk
- python313Packages.webexpythonsdk
- python314Packages.webexpythonsdk
- python312Packages.awsiotpythonsdk
- python313Packages.awsiotpythonsdk
- python314Packages.awsiotpythonsdk
- vscode-extensions.nsd.vscode-epics
- chickenPackages_5.chickenEggs.transducers
- @LeSuisse accepted
- @LeSuisse published on GitHub
Out of bounds stack write with crafted APL RR
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
References
-
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txt vendor-advisory
Affected products
- <4.14.3
Matching in nixpkgs
Ignored packages (20)
pkgs.pdnsd
Permanent DNS caching
-
nixos-unstable 1.2.9a-par
- nixpkgs-unstable 1.2.9a-par
- nixos-unstable-small 1.2.9a-par
-
nixos-26.05 1.2.9a-par
- nixos-26.05-small 1.2.9a-par
- nixpkgs-26.05-darwin 1.2.9a-par
pkgs.dnsdbq
C99 program that accesses passive DNS database systems
pkgs.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.dnsdiag
DNS Measurement, Troubleshooting and Security Auditing Toolset
pkgs.dnsdist
DNS Loadbalancer
pkgs.zeronsd
DNS server for ZeroTier users
pkgs.adidnsdump
Active Directory Integrated DNS dumping by any authenticated user
pkgs.perlPackages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl5Packages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl538Packages.nsdiff
None
pkgs.perl540Packages.nsdiff
None
pkgs.idrisPackages.transducers
Composable algorithmic transformation
-
nixos-unstable 2017-07-28
- nixpkgs-unstable 2017-07-28
- nixos-unstable-small 2017-07-28
-
nixos-26.05 2017-07-28
- nixos-26.05-small 2017-07-28
- nixpkgs-26.05-darwin 2017-07-28
pkgs.python312Packages.webexpythonsdk
None
pkgs.python313Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python314Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python312Packages.awsiotpythonsdk
None
pkgs.python313Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.python314Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.vscode-extensions.nsd.vscode-epics
EPICS syntax highlighting and tools
Package maintainers
-
@ruuda Ruud van Asseldonk <dev+nix@veniogames.com>
8.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
20 packages
- pdnsd
- dnsdbq
- nsdiff
- dnsdiag
- dnsdist
- zeronsd
- adidnsdump
- perlPackages.nsdiff
- perl5Packages.nsdiff
- perl538Packages.nsdiff
- perl540Packages.nsdiff
- idrisPackages.transducers
- python312Packages.webexpythonsdk
- python313Packages.webexpythonsdk
- python314Packages.webexpythonsdk
- python312Packages.awsiotpythonsdk
- python313Packages.awsiotpythonsdk
- python314Packages.awsiotpythonsdk
- chickenPackages_5.chickenEggs.transducers
- vscode-extensions.nsd.vscode-epics
- @LeSuisse accepted
- @LeSuisse published on GitHub
Heap overflow and crash with crafted SVCB RR
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
References
-
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12244.txt vendor-advisory
Affected products
- <4.14.3
Matching in nixpkgs
Ignored packages (20)
pkgs.pdnsd
Permanent DNS caching
-
nixos-unstable 1.2.9a-par
- nixpkgs-unstable 1.2.9a-par
- nixos-unstable-small 1.2.9a-par
-
nixos-26.05 1.2.9a-par
- nixos-26.05-small 1.2.9a-par
- nixpkgs-26.05-darwin 1.2.9a-par
pkgs.dnsdbq
C99 program that accesses passive DNS database systems
pkgs.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.dnsdiag
DNS Measurement, Troubleshooting and Security Auditing Toolset
pkgs.dnsdist
DNS Loadbalancer
pkgs.zeronsd
DNS server for ZeroTier users
pkgs.adidnsdump
Active Directory Integrated DNS dumping by any authenticated user
pkgs.perlPackages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl5Packages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl538Packages.nsdiff
None
pkgs.perl540Packages.nsdiff
None
pkgs.idrisPackages.transducers
Composable algorithmic transformation
-
nixos-unstable 2017-07-28
- nixpkgs-unstable 2017-07-28
- nixos-unstable-small 2017-07-28
-
nixos-26.05 2017-07-28
- nixos-26.05-small 2017-07-28
- nixpkgs-26.05-darwin 2017-07-28
pkgs.python312Packages.webexpythonsdk
None
pkgs.python313Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python314Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python312Packages.awsiotpythonsdk
None
pkgs.python313Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.python314Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.vscode-extensions.nsd.vscode-epics
EPICS syntax highlighting and tools
Package maintainers
-
@ruuda Ruud van Asseldonk <dev+nix@veniogames.com>
8.2 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
20 packages
- pdnsd
- dnsdbq
- nsdiff
- dnsdiag
- dnsdist
- zeronsd
- adidnsdump
- perlPackages.nsdiff
- perl5Packages.nsdiff
- perl538Packages.nsdiff
- perl540Packages.nsdiff
- idrisPackages.transducers
- python312Packages.webexpythonsdk
- python313Packages.webexpythonsdk
- python314Packages.webexpythonsdk
- python312Packages.awsiotpythonsdk
- python313Packages.awsiotpythonsdk
- python314Packages.awsiotpythonsdk
- vscode-extensions.nsd.vscode-epics
- chickenPackages_5.chickenEggs.transducers
- @LeSuisse accepted
- @LeSuisse published on GitHub
Bypass of client certificate verification with transfer over TLS
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
References
-
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt vendor-advisory
Affected products
- <4.14.3
Matching in nixpkgs
Ignored packages (20)
pkgs.pdnsd
Permanent DNS caching
-
nixos-unstable 1.2.9a-par
- nixpkgs-unstable 1.2.9a-par
- nixos-unstable-small 1.2.9a-par
-
nixos-26.05 1.2.9a-par
- nixos-26.05-small 1.2.9a-par
- nixpkgs-26.05-darwin 1.2.9a-par
pkgs.dnsdbq
C99 program that accesses passive DNS database systems
pkgs.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.dnsdiag
DNS Measurement, Troubleshooting and Security Auditing Toolset
pkgs.dnsdist
DNS Loadbalancer
pkgs.zeronsd
DNS server for ZeroTier users
pkgs.adidnsdump
Active Directory Integrated DNS dumping by any authenticated user
pkgs.perlPackages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl5Packages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl538Packages.nsdiff
None
pkgs.perl540Packages.nsdiff
None
pkgs.idrisPackages.transducers
Composable algorithmic transformation
-
nixos-unstable 2017-07-28
- nixpkgs-unstable 2017-07-28
- nixos-unstable-small 2017-07-28
-
nixos-26.05 2017-07-28
- nixos-26.05-small 2017-07-28
- nixpkgs-26.05-darwin 2017-07-28
pkgs.python312Packages.webexpythonsdk
None
pkgs.python313Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python314Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python312Packages.awsiotpythonsdk
None
pkgs.python313Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.python314Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.vscode-extensions.nsd.vscode-epics
EPICS syntax highlighting and tools
Package maintainers
-
@ruuda Ruud van Asseldonk <dev+nix@veniogames.com>
8.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
20 packages
- pdnsd
- dnsdbq
- nsdiff
- dnsdiag
- dnsdist
- zeronsd
- adidnsdump
- perlPackages.nsdiff
- perl5Packages.nsdiff
- perl538Packages.nsdiff
- perl540Packages.nsdiff
- idrisPackages.transducers
- python312Packages.webexpythonsdk
- python313Packages.webexpythonsdk
- python314Packages.webexpythonsdk
- python312Packages.awsiotpythonsdk
- python313Packages.awsiotpythonsdk
- python314Packages.awsiotpythonsdk
- vscode-extensions.nsd.vscode-epics
- chickenPackages_5.chickenEggs.transducers
- @LeSuisse accepted
- @LeSuisse published on GitHub
Denial of DNS over TLS service by any DoT client
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
References
-
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt vendor-advisory
Affected products
- <4.14.3
Matching in nixpkgs
Ignored packages (20)
pkgs.pdnsd
Permanent DNS caching
-
nixos-unstable 1.2.9a-par
- nixpkgs-unstable 1.2.9a-par
- nixos-unstable-small 1.2.9a-par
-
nixos-26.05 1.2.9a-par
- nixos-26.05-small 1.2.9a-par
- nixpkgs-26.05-darwin 1.2.9a-par
pkgs.dnsdbq
C99 program that accesses passive DNS database systems
pkgs.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.dnsdiag
DNS Measurement, Troubleshooting and Security Auditing Toolset
pkgs.dnsdist
DNS Loadbalancer
pkgs.zeronsd
DNS server for ZeroTier users
pkgs.adidnsdump
Active Directory Integrated DNS dumping by any authenticated user
pkgs.perlPackages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl5Packages.nsdiff
Create a "nsupdate" script from DNS zone file differences
pkgs.perl538Packages.nsdiff
None
pkgs.perl540Packages.nsdiff
None
pkgs.idrisPackages.transducers
Composable algorithmic transformation
-
nixos-unstable 2017-07-28
- nixpkgs-unstable 2017-07-28
- nixos-unstable-small 2017-07-28
-
nixos-26.05 2017-07-28
- nixos-26.05-small 2017-07-28
- nixpkgs-26.05-darwin 2017-07-28
pkgs.python312Packages.webexpythonsdk
None
pkgs.python313Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python314Packages.webexpythonsdk
Python module for Webex Teams APIs
pkgs.python312Packages.awsiotpythonsdk
None
pkgs.python313Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.python314Packages.awsiotpythonsdk
Python SDK for connecting to AWS IoT
pkgs.vscode-extensions.nsd.vscode-epics
EPICS syntax highlighting and tools
Package maintainers
-
@ruuda Ruud van Asseldonk <dev+nix@veniogames.com>