CVE-2026-12246: Out of bounds stack write with crafted APL RR
Last updated 29 June 2026
Other sources
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nsdto a version that resolves this vulnerability.Fixed in 4.3.5-1Fixed in 4.6.1-1Fixed in 4.12.0-1Fixed in 4.14.3-1 - Upgrade
Upgrade
NSDto a version that resolves this vulnerability.Fixed in 4.14.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12246?
The severity of CVE-2026-12246 is rated high with a CVSS score of 7.2.
How do I fix CVE-2026-12246?
To fix CVE-2026-12246, update to the latest version of NSD that addresses this vulnerability.
What impact does CVE-2026-12246 have on my system?
CVE-2026-12246 can lead to an out of bounds stack write which may allow an attacker to execute arbitrary code.
Who is affected by CVE-2026-12246?
CVE-2026-12246 affects users of NSD version 4.14.0 or earlier.
What kind of attack is associated with CVE-2026-12246?
CVE-2026-12246 is associated with an input validation issue, allowing crafted requests to potentially exploit the vulnerability.