oss-sec mailing list archives

NSD 4.15.1 security release


From: Willem Toorop <willem () nlnetlabs nl>
Date: Fri, 28 Aug 2026 12:12:25 +0200

Several vulnerabilities were found in NSD.
We released 4.15.1 as a security release on Wednesday 26 August including the relevant fixes.

The overview of the vulnerabilities with a brief description is:

CVE-2026-18664 - severity: HIGH
Wrong interpretation of ACL ranges

CVE-2026-18916 - severity: MEDIUM
Remote TCP DoS by throttling the TCP receive window

CVE-2026-19401 - severity: HIGH
Remote UDP DoS by sending multiple DNS Cookie options

CVE-2026-19538 - severity: HIGH
Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS

You can find detailed information on each vulnerability attached to this email along with their respective patches.

For ease of deployment we also provide a combined patch including all of them (patch_combined-4.15.1.diff).

The patches are tested to apply/work on 4.15.0.


Best regards,
-- Willem, on behalf of the NSD team.

Attachment: CVE-2026-18664.txt
Description:

Attachment: patch_CVE-2026-18664.diff
Description:

Attachment: CVE-2026-18916.txt
Description:

Attachment: patch_CVE-2026-18916.diff
Description:

Attachment: CVE-2026-19401.txt
Description:

Attachment: patch_CVE-2026-19401.diff
Description:

Attachment: CVE-2026-19538.txt
Description:

Attachment: patch_CVE-2026-19538.diff
Description:

Attachment: patch_combined-4.15.1.diff
Description:

Attachment: OpenPGP_0xE5F8F8212F77A498.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature


Current thread: