Improper access control in NSD - CVE-2026-19538
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote user to bypass IP-based access controls.
The vulnerability exists due to improper access control in the proxy protocol port handling when processing a repeated query over a kept-open TCP or TLS connection. A remote user can send the same query twice on a persistent connection to bypass IP-based access controls.
This issue affects BLOCKED access control list items and may allow spoofing of arbitrary IP addresses for queries, transfers, and notifies.
Affected software
Fedora
nsd
How to mitigate CVE-2026-19538
nsd - addressed in versions 4.15.1-1.el9, 4.15.1-1.el10_2, 4.15.1-1.el10_3, 4.15.1-1.el10_4, 4.15.1-1.fc43, 4.15.1-1.fc44, 4.15.1-1.fc45