Use-after-free in NSD - CVE-2026-12245
Published: June 25, 2026
NSD
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in error logging on TLS connections when handling a DNS query over a DNS over TLS connection that is closed before the response is read. A remote attacker can send a DNS query over a DNS over TLS connection and close the connection early to cause a denial of service.
Only instances configured to use DNS over TLS are vulnerable.