CVE-2026-12245

Name
CVE-2026-12245
Description
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
sep@nlnetlabs.nl https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:* nsd >= 4.13.0 < 4.14.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nsd edge-main 4.14.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
nsd edge-main 4.14.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.14.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.14.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.13.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.24-main 4.14.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
nsd 3.24-main 4.14.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.23-main 4.13.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable