Executive brief
NLnet Labs NSD, a popular open-source DNS server, contains a vulnerability that could allow a malicious or compromised primary server to crash or take control of secondary servers. By sending a specially crafted DNS record during a zone transfer, an attacker can cause a memory error that leads to a service outage or potential unauthorized code execution. This is particularly concerning for organizations running multi-tenant DNS environments where they act as a secondary server for external parties.
Technical details
A heap-based buffer overflow exists in NSD versions 4.14.0 through 4.14.2 due to an integer overflow (CWE-190) when handling SVCB Resource Records (RR). When NSD acts as a secondary server, a primary server can send an AXFR containing a crafted SVCB RR with an rdata size of 65512 bytes. This causes a 16-bit unsigned integer (uint16_t) used for memory allocation to wrap around when calculating the total size (exceeding 65535), leading to an undersized heap allocation. Subsequent processing allows a controlled heap write of up to 65509 bytes, potentially enabling Remote Code Execution (RCE). The vulnerability is patched in NSD version 4.14.3.
Affected products
- NLnet Labs NSD 4.14.0 to 4.14.2
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory
- 2026-06-25: patched: Fixed in version 4.14.3