| Release | Version |
|---|---|
| bullseye | 4.3.5-1 |
| bookworm | 4.6.1-1 |
| trixie | 4.12.0-1 |
| forky | 4.15.0-1 |
| sid | 4.15.1-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-19538 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | The BLOCKED access control list items that are evaluated to deny acces ... |
| CVE-2026-19401 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | Any remote client can crash a (debugging/non-release build type) NSD s ... |
| CVE-2026-18916 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | Any remote client can crash a NSD serve child, by throttling the TCP r ... |
| CVE-2026-18664 | vulnerable | vulnerable | vulnerable | vulnerable | fixed | When ranges are used for access control (i.e. of the form 1.2.3.4-1.2. ... |
| CVE-2026-12490 | fixed | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | When a provide-xfr is given with a tls-auth-name, a secondary requesti ... |
| Bug | Description |
|---|---|
| CVE-2026-12246 | NSD version 4.14.0 introduced a bug where a specially crafted APL RR, ... |
| CVE-2026-12245 | NSD from version 4.13.0 has a heap use-after-free bug in logging error ... |
| CVE-2026-12244 | If NSD is configured as secondary for a zone, the primary of that zone ... |
| CVE-2020-28935 | NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs ... |
| CVE-2019-13207 | nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflo ... |
| CVE-2016-6173 | NSD before 4.1.11 allows remote DNS master servers to cause a denial o ... |
| CVE-2009-1755 | Off-by-one error in the packet_read_query_section function in packet.c ... |
| DSA / DLA | Description |
|---|---|
| DSA-1803-1 | nsd nsd3 - denial of service |