CVE-2026-18916

EUVD-2026-66348
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
Wrap or Wraparound
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.73%
Debian logo
Debian Releases
Debian Product
Codename
nsd
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
4.15.1-1
fixed
trixie
vulnerable