Yasuhiro Morishita[verified]@OrangeMorishitaDisclosure
The passage announces two new CVEs: CVE‑2026‑12244 is a heap‐overflow flaw in nsd triggered by specially crafted SVCB records that could lead to remote code execution, and CVE‑2026‑12245 is a use‑after‑free issue in the DoT implementation that can be abused for denial‑of‑service attacks.
Shirouzu Hiroaki(白水啓章)[verified]@shirouzuGeneral
The message informs that Debian nsd is not affected by CVE‑2026‑12244‑12246, only by CVE‑2026‑12490, and notes the TLS certificate bypass in secondary zone transfers, but indicates it may not impact the speaker’s static‑IP setup.
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
An alert states that vulnerability information for four CVEs (CVE-2026-12244, CVE-2026-12245, CVE-2026-12246, CVE-2026-12490) pertaining to NSD has been published, but includes no additional details on exploits, patches, or technical specifics.
Open Source Security mailing list@oss_securityPatch
NLnet Labs announced that four high‑severity CVEs were addressed in NSD 4.14.3, providing fixes for heap overflow, DNS‑over‑TLS denial, out‑of‑bounds stack writes, and a client‑certificate bypass.
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
The announcement reports that vulnerability information for four CVEs has been made public, with no additional technical or remediation details provided.
Daily CyberSecurity@the_yellow_fallPatch
NLnet Labs released a patch for CVE‑2026‑12244 and other critical NSD DNS vulnerabilities, urging users with multi‑tenant secondary DNS deployments to update immediately.