Security Advisory

CVE-2026-12246

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-25 05:24:29
Last updated 2026-06-25 12:42:05
Assigner NLnet Labs
CVSS score 7.2
State PUBLISHED

Description

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.