Impact
The vulnerability allows any remote client to crash one of the NSD child processes by sending a specially crafted DNS query that includes a precise number of DNS Cookie options. This exploitation can cause the serve‑child to terminate unexpectedly, leading to a denial of DNS service for all clients that depend on that process. Because the fault occurs in a debugging or non‑release build, the crash is not mitigated by production code paths, allowing the attacker to repeatedly crash the server. The high CVSS score of 8.2 reflects the seriousness of this DoS capability.
Affected Systems
The flaw affects NLnet Labs’ NSD when running versions prior to 4.15.1 in debugging or non‑release build modes. Any deployment of an older NSD instance that includes such build types is vulnerable. The issue is fixed in 4.15.1 and all later releases, so upgrading to 4.15.1 or newer removes the risk.
Risk and Exploitability
The attack vector is remote over UDP DNS; an attacker can send crafted packets from any location on the network to the DNS server. The flaw is highly exploitable because it does not require elevated privileges or special access, and the exploitation path is straightforward—sending a DNS query with the exact number of Cookie options to trigger the crash. The EPSS score is currently unavailable, but the CVSS score of 8.2 and its absence from CISA KEV suggest a moderate to high likelihood of real‑world exploitation, especially if the attacker can position themselves close to the DNS server or directly target the port.
OpenCVE Enrichment