Ubuntu alert USN-8474-1 (NSD)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8474-1] NSD vulnerabilities | |
| Date: | Thu, 25 Jun 2026 14:40:19 +0000 | |
| Message-ID: | <E1wclFb-0001Sf-0Z@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8474-1 June 25, 2026 NSD vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: NSD could be made to crash or run programs if it received specially crafted network traffic. Software Description: - nsd: Several security issues were fixed in NSD, including a stack-based buffer overflow in APL resource record handling, a heap overflow in SVCB resource record handling, a use-after-free in TLS connection error logging, and a TLS authentication bypass for zone transfers. Details: It was discovered that NSD incorrectly handled APL resource records with an address length larger than permitted for the address family. A remote attacker could use this to cause a stack-based buffer overflow when the zone is written to disk, potentially executing arbitrary code with the privileges of the NSD server. (CVE-2026-12246) It was discovered that NSD incorrectly handled SVCB resource records. A remote attacker could use this to cause a heap overflow, potentially executing arbitrary code with the privileges of the NSD server. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-12244) It was discovered that NSD had a use-after-free vulnerability in TLS connection error logging. A remote attacker could use this to cause a denial of service by crashing the server process. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-12245) It was discovered that NSD incorrectly handled TLS authentication for zone transfers. An attacker could bypass transfer security restrictions when certain conditions were met. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-12490) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS nsd 4.14.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS nsd 4.8.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS nsd 4.3.9-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS nsd 4.1.26-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS nsd 4.1.17-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS nsd 4.1.7-1ubuntu0.1~esm1 Available with Ubuntu Pro nsd3 4.1.7-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8474-1 CVE-2026-12244, CVE-2026-12245, CVE-2026-12246, CVE-2026-12490
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo9LYcACgkQcpJm3tlz hgFcPA//YerCgCiJ7pqGluiu+IAL61DiG7D05FgP8Q25V4GYNjGGp/G8vYfTJ69v SDZ1QAEsm6Mx2GBeluP4wY1ftdIgrlZu1Rw/eIr70j0TjSZ3RS+fw1TtwHJdWhea Jm6wvixamuWr9VMEO3sfoLvakojbHsrsNHxB4lz903N+HkvpjLBY+yZVb0/aZLwn lqIEArU2j7oCYU2dORUpoJiOJNRffnmNiYEzNNr5Zdz2TR2EEDXPSeDSUHkQ7DoZ scAv0x8fDfr7G2AH7KSoXzfNNQ9oS1Zn8TNM0r5miEMG91oDT3zie74zwLbMox3D A+X0bZB3q4pvZGcJxRVeQO0sAt/mruYa5SUaFSIaOcMtRwxDyPaWehr+H+JHfvqk u5wNAbN3AP3+j8QVISCPHbNfdPUzRbbnI4HBGf7Vx7kGYUcnEmNVl53WMkG9+7a2 s557SJWKzKyrJt91B5J/e5UwhIpZ82J8ECaGZ0szVYGBUPzSnIbyMYSfmGNg2IoE nfzoRUGv32McBRY4vAKEYL7k0SifI5kxxhglBmmvV1RYAYA71SiMlBABWp39TBvI pbiANRLGxjuLLHn6ZNezA0RjUp0nss+0aJqL5gjUw/G2HuN1Q48O0jgDC1alZZv0 uchG8pudc2Owq61s0TP3y2ZOjdrtgmDxy6DZRBixlPq8vOtYaGk= =T25o -----END PGP SIGNATURE-----
