|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2026-0b77a23312 (nsd)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 43 Update: nsd-4.15.0-1.fc43
Date:  Mon, 03 Aug 2026 01:05:27 +0000
Message-ID:  <20260803010527.BD5D376547@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0b77a23312 2026-08-03 01:04:56.884850+00:00 -------------------------------------------------------------------------------- Name : nsd Product : Fedora 43 Version : 4.15.0 Release : 1.fc43 URL : http://www.nlnetlabs.nl/nsd/ Summary : Fast and lean authoritative DNS Name Server Description : NSD is a complete implementation of an authoritative DNS name server. For further information about what NSD is and what NSD is not please consult the REQUIREMENTS document which is a part of this distribution. -------------------------------------------------------------------------------- Update Information: FEATURES: Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from metric name to label BUG FIXES: Fix #478: Feature request: reduce syslog noise from frequent read-only control commands (e.g. stats_noreset). It logs the verbosity command always, and others at 2 and higher. Fix XDP cleanup code being executed even if xdp is not configured Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources Merge #484 from orlitzky: OpenRC: fix network deps and support both supervisors Fix PROXYv2 header read and consume, it checks the header size. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix notify relay ipc to check for large size. This stops desync of the internal notify pipe. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix print of malformed HIP records. Thanks to Qifan Zhang, Palo Alto Networks, for the report, and Haruki Oyama (Waseda University) for also reporting this issue. Fix to not fail on NSEC3 records with a bad owner name. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix print of NXT RR without bitmap Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix overflow for NSEC3 zones with 255-octet name Thanks to Haruki Oyama (Waseda University) for the report, and Qifan Zhang, Palo Alto Networks, for also reporting this issue. Fix to update github ci actions/checkout to v7. Fix notify and zone transfer processing for malformed SOA records, with a short rdata content. It stops an assertion failure. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. Fix that wrong buffer position in IXFR for the first SOA causes the storage to retrieve wrong information. Later data would overwrite it so it did not cause observable trouble. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. More robust removing of RRs from an IXFR processing. Thanks zhangph for reporting this issue Fix unit test for stopmany for process role logs. Fix nsd-control assoc_tsig, if that interrupts a zone transfer in progress, to not crash. It restarts the transfer from the primary. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix nsd-control del_tsig, if that interrupts a zone transfer in progress, to not crash. It does not delete the key, if in use. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog producer zone with long name, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog consumer zone with long name for member unique label that is long, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that non-IN-class records cause a zone transfer to be rejected. Also such records are not added from a transfer. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to disallow a SOA record in the middle of an AXFR. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY. This stops an assertion failure. Also fix soa and ns rrset change in IXFR when packed rrsets are disabled. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to handle NSEC3 zones without space for hashes. Zones with a apex domain name length >= 223 bytes, that have a NSEC3PARAM must not be prehashed, since the hashed owner name would not fit. Thanks Qifan Zhang, Palo Alto Networks, for the report Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix for xfrd crash with too short response to a UDP SOA query Only for release builds and only when configured for XFR over UDP Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that out-of-zone records are skipped from zone transfers. Otherwise such records could stick around after zone deletion and cause failures for DS queries. Thanks to Qifan Zhang, Palo Alto Networks, for the report. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 25 2026 Fabio Alessandro Locati <mail@fale.io> - 4.15.0-1 - Update to 4.15.0. Fixes rhbz#2497645 * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 4.14.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494181 - CVE-2026-12490 nsd: Bypass of client certificate verification with transfer over TLS [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494181 [ 2 ] Bug #2494182 - CVE-2026-12490 nsd: Bypass of client certificate verification with transfer over TLS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494182 [ 3 ] Bug #2494183 - CVE-2026-12246 nsd: Out of bounds stack write with crafted APL RR [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494183 [ 4 ] Bug #2494184 - CVE-2026-12246 nsd: Out of bounds stack write with crafted APL RR [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494184 [ 5 ] Bug #2494185 - CVE-2026-12245 nsd: Denial of DNS over TLS service by any DoT client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494185 [ 6 ] Bug #2494186 - CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494186 [ 7 ] Bug #2494187 - CVE-2026-12245 nsd: Denial of DNS over TLS service by any DoT client [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494187 [ 8 ] Bug #2494188 - CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494188 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0b77a23312' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds