Nlnetlabs

Nsd

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 26.08.2026 08:47:08
  • Zuletzt bearbeitet 08.09.2026 19:59:34

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

  • EPSS 0.33%
  • Veröffentlicht 26.08.2026 08:44:08
  • Zuletzt bearbeitet 08.09.2026 20:00:05

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs,...

  • EPSS 0.33%
  • Veröffentlicht 26.08.2026 08:39:12
  • Zuletzt bearbeitet 08.09.2026 20:00:51

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

  • EPSS 0.32%
  • Veröffentlicht 26.08.2026 08:34:22
  • Zuletzt bearbeitet 08.09.2026 20:02:34

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied a...

  • EPSS 0.16%
  • Veröffentlicht 25.06.2026 05:24:41
  • Zuletzt bearbeitet 26.06.2026 02:08:03

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the...

  • EPSS 0.3%
  • Veröffentlicht 25.06.2026 05:24:29
  • Zuletzt bearbeitet 26.06.2026 02:07:47

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

  • EPSS 0.32%
  • Veröffentlicht 25.06.2026 05:24:18
  • Zuletzt bearbeitet 26.06.2026 02:07:41

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without readi...

  • EPSS 0.33%
  • Veröffentlicht 25.06.2026 05:24:08
  • Zuletzt bearbeitet 26.06.2026 02:07:23

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space ne...

  • EPSS 3.45%
  • Veröffentlicht 05.11.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 01:57:54

Cache Poisoning issue exists in DNS Response Rate Limiting.

  • EPSS 2.92%
  • Veröffentlicht 09.02.2017 15:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.