Vulnerability Description
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Nsd | >= 4.14.0, < 4.14.3 |
Related Weaknesses (CWE)
References
- https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12246.txtPatchVendor Advisory
FAQ
What is CVE-2026-12246?
CVE-2026-12246 is a vulnerability with a CVSS score of 8.1 (HIGH). NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a m...
How severe is CVE-2026-12246?
CVE-2026-12246 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12246?
Check the references section above for vendor advisories and patch information. Affected products include: Nlnetlabs Nsd.