CVE-2026-12244Disclosure(nlnetlabs / nsd)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs nsd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsd

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-29); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
nsd

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-29: 2Mentions · 2026-06-30: 1Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-29: 106-2506-2606-2906-3007-06
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-06-261
Patch1
2026-06-292
Disclosure1General1
2026-06-301
Patch1
2026-07-061
Disclosure1
Full discourse6 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490) https://jprs.jp/tech/security/2026-06-29-nsd.html

    Post summary

    An alert states that vulnerability information for four CVEs (CVE-2026-12244, CVE-2026-12245, CVE-2026-12246, CVE-2026-12490) pertaining to NSD has been published, but includes no additional details on exploits, patches, or technical specifics.

    031601.4K
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    CVE-2026-12244:特別に細工されたSVCBレコードでセカンダリサーバーのnsdをヒープオーバーフロー可能。最悪の場合RCE。 CVE-2026-12245:DoTの実装不具合でuse-after-free、外部からDoS攻撃可能。 (続く)

    Post summary

    The passage announces two new CVEs: CVE‑2026‑12244 is a heap‐overflow flaw in nsd triggered by specially crafted SVCB records that could lead to remote code execution, and CVE‑2026‑12245 is a use‑after‑free issue in the DoT implementation that can be abused for denial‑of‑service attacks.

    12041224
    4.5K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    NLnet Labs NSD: 4 "high" CVEs fixed in 4.14.3 https://www.openwall.com/lists/oss-security/2026/06/25/9 CVE-2026-12244: Heap overflow with crafted SVCB RR CVE-2026-12245: Denial of DNS over TLS service CVE-2026-12246: Out of bounds stack write with crafted APL RR CVE-2026-12490: Bypass of client certificate

    Post summary

    NLnet Labs announced that four high‑severity CVEs were addressed in NSD 4.14.3, providing fixes for heap overflow, DNS‑over‑TLS denial, out‑of‑bounds stack writes, and a client‑certificate bypass.

    01050777
    4.7K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【メールマガジン(FROM JPRS)】最新号を掲載しました。 通常号 vol.1252「NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490)、他2件」など https://jprs.jp/mail/backnumber/2026/260706.html

    Post summary

    The announcement reports that vulnerability information for four CVEs has been made public, with no additional technical or remediation details provided.

    00031367
    1.3K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    NLnet Labs patched critical NSD DNS vulnerabilities, including CVE-2026-12244. Update now to protect your multi-tenant secondary DNS deployments. #NSDDNS #CyberSecurity #Vulnerability #CVE202612244 https://securityonline.info/nsd-dns-vulnerabilities-patched https://t.co/QZJaLaqVVo

    Post summary

    NLnet Labs released a patch for CVE‑2026‑12244 and other critical NSD DNS vulnerabilities, urging users with multi‑tenant secondary DNS deployments to update immediately.

    00010558
    12.9K followersView on X
  • Shirouzu Hiroaki(白水啓章)@shirouzu
    General

    Debian(trixe) の nsd だと CVE-2026-12244~12246 は対象外で、唯一 12490 が対象だけど、secondary xfr が TLS証明の迂回されるという話。 ウチは IPアドレス固定でセカンダリ指定&TLS証明を使ってないので関係なさそうかな? (最近の例と同じく、Qifan Zhang氏による報告と)

    Post summary

    The message informs that Debian nsd is not affected by CVE‑2026‑12244‑12246, only by CVE‑2026‑12490, and notes the TLS certificate bypass in secondary zone transfers, but indicates it may not impact the speaker’s static‑IP setup.

    01000497
    2.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsnsd---

Explore more