Junglewise Threat Intelligence

CVE-2026-12244: NLnet Labs NSD heap overflow in SVCB RR processing

CVE-2026-12244 · Severity: info · CVSS 8.7 · Published 2026-06-25

Vendors: NLnet Labs.

Executive brief

NLnet Labs NSD, a popular open-source DNS server, contains a vulnerability that could allow a malicious or compromised primary server to crash or take control of secondary servers. By sending a specially crafted DNS record during a zone transfer, an attacker can cause a memory error that leads to a service outage or potential unauthorized code execution. This is particularly concerning for organizations running multi-tenant DNS environments where they act as a secondary server for external parties.

Technical details

A heap-based buffer overflow exists in NSD versions 4.14.0 through 4.14.2 due to an integer overflow (CWE-190) when handling SVCB Resource Records (RR). When NSD acts as a secondary server, a primary server can send an AXFR containing a crafted SVCB RR with an rdata size of 65512 bytes. This causes a 16-bit unsigned integer (uint16_t) used for memory allocation to wrap around when calculating the total size (exceeding 65535), leading to an undersized heap allocation. Subsequent processing allows a controlled heap write of up to 65509 bytes, potentially enabling Remote Code Execution (RCE). The vulnerability is patched in NSD version 4.14.3.

Affected products

  • NLnet Labs NSD 4.14.0 to 4.14.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory
  • 2026-06-25: patched: Fixed in version 4.14.3

References