Use-after-free in NSD - CVE-2026-12245
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in error logging on TLS connections when handling a DNS query over a DNS over TLS connection that is closed before the response is read. A remote attacker can send a DNS query over a DNS over TLS connection and close the connection early to cause a denial of service.
Only instances configured to use DNS over TLS are vulnerable.
Affected software
Fedora
Ubuntu
nsd (Ubuntu package)
nsd
How to mitigate CVE-2026-12245
nsd (Ubuntu package) - addressed in versions 4.1.7-1ubuntu0.1~esm1, 4.1.17-1ubuntu0.1~esm1, 4.1.26-1ubuntu0.1~esm1, 4.3.9-1ubuntu0.1~esm1, 4.8.0-1ubuntu0.1~esm1, 4.14.0-1ubuntu0.1~esm1
nsd - addressed in versions 4.14.3-1.fc43, 4.14.3-1.fc44, 4.15.0-1.el10_3