Home / mailings [USN-8474-1] NSD vulnerabilities
Posted on 25 June 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8474-1
June 25, 2026
NSD vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
NSD could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- nsd: Several security issues were fixed in NSD, including a stack-based buffer overflow in APL resource record handling, a heap overflow in SVCB resource record handling, a use-after-free in TLS connection error logging, and a TLS authentication bypass for zone transfers.
Details:
It was discovered that NSD incorrectly handled APL resource records with an
address length larger than permitted for the address family. A remote attacker
could use this to cause a stack-based buffer overflow when the zone is written
to disk, potentially executing arbitrary code with the privileges of the NSD
server. (CVE-2026-12246)
It was discovered that NSD incorrectly handled SVCB resource records. A remote
attacker could use this to cause a heap overflow, potentially executing
arbitrary code with the privileges of the NSD server. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-12244)
It was discovered that NSD had a use-after-free vulnerability in TLS
connection error logging. A remote attacker could use this to cause a denial
of service by crashing the server process. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-12245)
It was discovered that NSD incorrectly handled TLS authentication for zone
transfers. An attacker could bypass transfer security restrictions when
certain conditions were met. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-12490)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
nsd 4.14.0-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
nsd 4.8.0-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
nsd 4.3.9-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
nsd 4.1.26-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
nsd 4.1.17-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
nsd 4.1.7-1ubuntu0.1~esm1
Available with Ubuntu Pro
nsd3 4.1.7-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8474-1
CVE-2026-12244, CVE-2026-12245, CVE-2026-12246, CVE-2026-12490
--===============2967589999153313480==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
