任何远程客户端都可以通过发送一条精心构造的消息,导致运行调试版或非发布版类型的 NSD 服务子进程崩溃。该消息包含一个经过特殊调优的 DNS Cookie 选项数量(当 UDP 负载大小为 512 字节时,该数量为 17)。通过持续崩溃这些服务子进程,远程客户端可以严重阻碍 DNS 服务的正常运行;如果攻击者位于网络拓扑中足够靠近目标的位置,甚至可能导致所有 DNS 服务完全不可用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | NSD | 4.3.7< 4.15.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | NSD | 4.3.7 ~ 4.15.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18664 | 8.2 HIGH | Wrong interpretation of ACL ranges |
| CVE-2026-19538 | 8.2 HIGH | Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS |
| CVE-2026-18916 | 6.9 MEDIUM | Remote TCP DoS by throttling the TCP receive window |
No comments yet