Stack Overflow Vulnerability in NSD Affecting NLnet Labs
CVE-2026-12246

7.2HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-12246?

A vulnerability exists in NSD version 4.14.0 that allows for a stack overflow when handling a specially crafted APL Resource Record (RR). The bug permits the 'adflength' to exceed the acceptable limit for the address family, resulting in the ability to overwrite the stack while writing the zone to disk. This presents a risk as attackers could exploit this weakness to manipulate system behavior by controlling up to 111 bytes on the stack.

Affected Version(s)

NSD 4.14.0 < 4.14.3

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang from Palo Alto Networks
Haruki Oyama from Waseda University
zhangph
.