CVE-2026-12246 PUBLISHED

Out of bounds stack write with crafted APL RR

Assigner: NLnet Labs
Reserved: 15.06.2026 Published: 25.06.2026 Updated: 25.06.2026

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Processing of a zone containing a crafted APL can crash NSD when writing the zone to disk. These zones can be provided by a trusted primary

Product Status

Vendor NLnet Labs
Product NSD
Versions Default: unaffected
  • affected from 4.14.0 to 4.14.3 (excl.)

Solutions

This issue is fixed starting with version 4.14.3.

Credits

  • Qifan Zhang from Palo Alto Networks finder
  • Haruki Oyama from Waseda University finder
  • zhangph finder

References

Problem Types

  • CWE-120: Buffer Copy without Checking Size of Input CWE
  • CWE-20: Improper Input Validation CWE