CVE-2026-12245
Description
A flaw was found in NSD. When NSD is configured with DNS over TLS (DoT), a remote attacker can exploit a vulnerability by performing a TLS action and then prematurely closing the connection. This action causes the server process to crash and restart. By repeatedly exploiting this flaw, an attacker can keep the server in a continuous crash-restart loop, leading to a denial of service for DoT clients.
Statement
This is an Important denial of service vulnerability in NSD when configured for DNS over TLS (DoT). A remote, unauthenticated attacker can trigger a server crash and restart by prematurely closing a TLS connection, leading to a continuous crash-restart loop and denying DoT service to legitimate clients. This impact is significant for environments relying on DoT for secure DNS resolution.
This vulnerability doesn't affect any supported Red Hat Product.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.