CVE-2026-12490

Description

A flaw was found in nsd. When a 'provide-xfr' is configured with a 'tls-auth-name', the server incorrectly allows zone transfers without requiring a client certificate if the request comes over TLS on the regular 'tls-port' or over TCP on the regular port, provided other access control conditions are met. This authentication bypass allows an attacker to perform unauthorized zone transfers, leading to information disclosure.

Statement

This flaw is rated as Moderate. The nsd DNS server, when configured for zone transfers with provide-xfr and tls-auth-name, can bypass client certificate verification. This allows unauthorized zone transfers and information disclosure if requests are made over the regular TLS or TCP port, as the tls-auth-xfr-only option is not enabled by default.

This vulnerability doesn't affect any supported Red Hat Product.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.