CVE-2026-12245: Denial of DNS over TLS service by any DoT client
Last updated 29 June 2026
Other sources
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nsdto a version that resolves this vulnerability.Fixed in 4.3.5-1Fixed in 4.6.1-1Fixed in 4.12.0-1Fixed in 4.14.3-1 - Upgrade
Upgrade
nsdto a version that resolves this vulnerability.Fixed in 4.14.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12245?
CVE-2026-12245 has a high severity rating of 8.7.
How do I fix CVE-2026-12245?
To fix CVE-2026-12245, update your NSD software to version 4.13.1 or later.
What type of vulnerability is CVE-2026-12245?
CVE-2026-12245 is a heap use-after-free vulnerability that affects DNS over TLS services.
What impact does CVE-2026-12245 have on my system?
CVE-2026-12245 can cause a denial of service by crashing the NSD server process.
Who is affected by CVE-2026-12245?
Any users running NSD version 4.13.0 are affected by CVE-2026-12245.