https://seclists.org/oss-sec/2026/q2/1029: Several vulnerabilities wefound in NLnet Labs NSD
Published Jun 25, 2026
·Updated
Affected Software
1 affected component
Nlnet Labs NSD=4.14.2
Frequently Asked Questions
1
What is the severity of CVE-2026-12244?
CVE-2026-12244 has a severity rating of HIGH due to a heap overflow and potential crash when handling crafted SVCB resource records.
2
How do I fix CVE-2026-12244?
To fix CVE-2026-12244, update your NLnet Labs NSD to the latest version that addresses this heap overflow vulnerability.
3
What impact does CVE-2026-12245 have on DNS services?
CVE-2026-12245 can cause a denial of DNS over TLS service by any malicious DoT client, impacting the availability of secure DNS.
4
How can I mitigate CVE-2026-12245?
Mitigation for CVE-2026-12245 involves applying the relevant patch to NLnet Labs NSD and implementing network access controls to limit the number of DoT clients.
5
Are there any workarounds for CVE-2026-12246?
There are currently no documented workarounds for CVE-2026-12246, so it is recommended to apply the fix once it is available.