openSUSE-SU-2026:0265-1: important: Security update for nsd
[email protected] Wed, 29 Jul 2026 12:04:43 +0200 (CEST)
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for nsd
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0265-1
Rating: important
References: #1269563 #1269564 #1269565 #1269566
Cross-References: CVE-2026-12244 CVE-2026-12245 CVE-2026-12246
CVE-2026-12490
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes four vulnerabilities is now available.
Description:
This update for nsd fixes the following issues:
- Update nsd.keyring
- update to 4.14.3:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_3_REL/doc/ChangeLog
* CVE-2026-12490: Bypass of client certificate verification with
transfer over TLS (boo#1269563)
* CVE-2026-12246: Out of bounds stack write with crafted APL RR
(boo#1269564)
* CVE-2026-12245: Denial of DNS over TLS service by any DoT client
(boo#1269565)
* CVE-2026-12244: Heap overflow and crash with crafted SVCB RR
(boo#1269566)
- update to 4.14.2:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_2_REL/doc/ChangeLog
- update to 4.14.1:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_1_REL/doc/ChangeLog
- update to 4.14.0:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_0_REL/doc/ChangeLog
- update to 4.13.0:
https://github.com/NLnetLabs/nsd/blob/NSD_4_13_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_12_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_12_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_11_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_11_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_10_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_10_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_9_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_9_0_REL/doc/ChangeLog
- enable systemd notify support.
- enable dnstap support.
- enable tcp fast open support
- enable support for >= 2038
- As far as it is known the kernel has a working recvmmsg pass
--enable-recvmmsg to configure.
- Don't --enable-mmap. Replacing malloc may sound attractive but all
safety checks to prevent corruption included in libc are lost.
- Provide user/group symbol for user created during pre.
- update to 4.8.0:
* Fix unit test kill_from_pidfile function for nonexistent files because
the argument is evaluated before the test expression.
* Fix rr-test to also convert the contents of the just written
output file.
* Fix test set to remove -f nsd.db and rm nsd.db commands.
* Fix test set to remove difffile option.
* Fix #14: Set timeout to 3s when servicing remaining TCP connections.
* Fix: Always instate write handler after reading queries from TCP.
* Answer first query on connections accepted just before reload.
* Merge #305: faster stats. Statistics can be gathered while a reload is
in progress.
* Remove on-disk database.
* Fix processing of consolidated IXFRs.
* Fix for interprocess communication to set quit sync command from main
process explicitly.
* Merge #281: Proxy protocol. An implementation of PROXYv2 for NSD.
* It can be configured with proxy-protocol-port: portnum with the port
number of the interface on which proxy traffic is handled.
* The interface can support proxy traffic for UDP, TCP and TLS.
* Fix autoconf 2.69 warnings in configure.
* Merge #287: Update nsd.conf.5.in.
* Fix unused variable warning in unit test of udb.
* Fix #284: dnstap_collector.c: SOCK_NONBLOCK is not available
on Mac/Darwin.
* Fix unused but set variable warning. bind8-stats and --without-ssl are
specified.
* Add missing items to doc/RELNOTES.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-265=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
nsd-4.14.3-bp157.2.3.1
References:
https://www.suse.com/security/cve/CVE-2026-12244.html
https://www.suse.com/security/cve/CVE-2026-12245.html
https://www.suse.com/security/cve/CVE-2026-12246.html
https://www.suse.com/security/cve/CVE-2026-12490.html
https://bugzilla.suse.com/1269563
https://bugzilla.suse.com/1269564
https://bugzilla.suse.com/1269565
https://bugzilla.suse.com/1269566