openSUSE-SU-2026:0265-1: important: Security update for nsd

[email protected] Wed, 29 Jul 2026 12:04:43 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for nsd
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0265-1
Rating:             important
References:         #1269563 #1269564 #1269565 #1269566 
Cross-References:   CVE-2026-12244 CVE-2026-12245 CVE-2026-12246
                    CVE-2026-12490
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes four vulnerabilities is now available.

Description:

   This update for nsd fixes the following issues:

   - Update nsd.keyring

   - update to 4.14.3:
     https://github.com/NLnetLabs/nsd/blob/NSD_4_14_3_REL/doc/ChangeLog
     * CVE-2026-12490: Bypass of client certificate verification with
       transfer over TLS (boo#1269563)
     * CVE-2026-12246: Out of bounds stack write with crafted APL RR
       (boo#1269564)
     * CVE-2026-12245: Denial of DNS over TLS service by any DoT client
       (boo#1269565)
     * CVE-2026-12244: Heap overflow and crash with crafted SVCB RR
       (boo#1269566)
   - update to 4.14.2:
     https://github.com/NLnetLabs/nsd/blob/NSD_4_14_2_REL/doc/ChangeLog
   - update to 4.14.1:
     https://github.com/NLnetLabs/nsd/blob/NSD_4_14_1_REL/doc/ChangeLog
   - update to 4.14.0:
     https://github.com/NLnetLabs/nsd/blob/NSD_4_14_0_REL/doc/ChangeLog

   - update to 4.13.0:
     https://github.com/NLnetLabs/nsd/blob/NSD_4_13_0_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_12_1_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_12_0_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_11_1_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_11_0_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_10_1_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_10_0_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_9_1_REL/doc/ChangeLog
     https://github.com/NLnetLabs/nsd/blob/NSD_4_9_0_REL/doc/ChangeLog
   - enable systemd notify support.
   - enable dnstap support.
   - enable tcp fast open support
   - enable support for >= 2038

   - As far as it is known the kernel has a working recvmmsg pass
     --enable-recvmmsg to configure.
   - Don't --enable-mmap. Replacing malloc may sound attractive but all
     safety checks to prevent corruption included in libc are lost.

   - Provide user/group symbol for user created during pre.

   - update to 4.8.0:
     * Fix unit test kill_from_pidfile function for nonexistent files because
       the argument is evaluated before the test expression.
     * Fix rr-test to also convert the contents of the just written
       output file.
     * Fix test set to remove -f nsd.db and rm nsd.db commands.
     * Fix test set to remove difffile option.
     * Fix #14: Set timeout to 3s when servicing remaining TCP connections.
     * Fix: Always instate write handler after reading queries from TCP.
     * Answer first query on connections accepted just before reload.
     * Merge #305: faster stats. Statistics can be gathered while a reload is
       in progress.
     * Remove on-disk database.
     * Fix processing of consolidated IXFRs.
     * Fix for interprocess communication to set quit sync command from main
       process explicitly.
     * Merge #281: Proxy protocol. An implementation of PROXYv2 for NSD.
     * It can be configured with proxy-protocol-port: portnum with the port
       number of the interface on which proxy traffic is handled.
     * The interface can support proxy traffic for UDP, TCP and TLS.
     * Fix autoconf 2.69 warnings in configure.
     * Merge #287: Update nsd.conf.5.in.
     * Fix unused variable warning in unit test of udb.
     * Fix #284: dnstap_collector.c: SOCK_NONBLOCK is not available
       on Mac/Darwin.
     * Fix unused but set variable warning. bind8-stats and --without-ssl are
       specified.
     * Add missing items to doc/RELNOTES.


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-265=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      nsd-4.14.3-bp157.2.3.1


References:

   https://www.suse.com/security/cve/CVE-2026-12244.html
   https://www.suse.com/security/cve/CVE-2026-12245.html
   https://www.suse.com/security/cve/CVE-2026-12246.html
   https://www.suse.com/security/cve/CVE-2026-12490.html
   https://bugzilla.suse.com/1269563
   https://bugzilla.suse.com/1269564
   https://bugzilla.suse.com/1269565
   https://bugzilla.suse.com/1269566