CVE-2026-18664
Description
A flaw was found in NSD. On systems using little-endian architecture, the software incorrectly compares IP addresses against defined Access Control List (ACL) ranges. This misinterpretation can lead to a bypass of intended access controls, where IP addresses that should be denied access are instead allowed, and vice versa. This could result in unauthorized access to resources or services.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate this issue, restrict network access to the NSD service using external firewall rules. Configure the firewall to only allow connections from trusted IP addresses or networks that are authorized to access the NSD server, thereby preventing unauthorized access attempts before they reach the vulnerable NSD access control logic. Ensure that any changes to firewall rules are thoroughly tested to avoid disrupting legitimate service.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
This can lead to incorrect results and resultant weaknesses. For example, the code might inadvertently compare references to objects, instead of the relevant contents of those objects, causing two "equal" objects to be considered unequal.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.