Impact
A remote client can crash an NSD child process by throttling the TCP receive window after a query. The child crash leads to a brief service interruption, and repeated crashes can render the NSD instance unable to serve any TCP traffic. The flaw corresponds to integer-related overflow or underflow weaknesses (CWE-191).
Affected Systems
The affected product is NLnet Labs NSD. Versions prior to 4.15.1 are vulnerable; the fix is included in 4.15.1 and later releases.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known broad exploitation yet. However, the flaw is exploitable from a remote host that can send crafted DNS queries over TCP. The attack requires no special credentials, making it straightforward for an adversary to mount a denial‑of‑service attack.
OpenCVE Enrichment