← Back

Nsd

nsd

Vendor: Nlnetlabs • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nlnetlabs
1Nsd
Jun 26, 2026
Jun 25, 2026
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the...Show more
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.Show less
1Nlnetlabs
1Nsd
Jun 26, 2026
Jun 25, 2026
7.2 HIGH· v4
8.1 HIGH· v3
N/A· v2
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attack...Show more
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.Show less
1Nlnetlabs
1Nsd
Jun 26, 2026
Jun 25, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closin...Show more
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.Show less
1Nlnetlabs
1Nsd
Jun 26, 2026
Jun 25, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable tha...Show more
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytesShow less
4Isc
NicNlnetlabs+1 more
4Bind
Enterprise LinuxKnot Resolver+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Cache Poisoning issue exists in DNS Response Rate Limiting.
1Nlnetlabs
1Nsd
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
1Nlnetlabs
1Nsd
Apr 29, 2026
Jul 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
1Nlnetlabs
1Nsd
Apr 23, 2026
May 22, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute ar...Show more
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.Show less