Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
This issue is fixed in 4.15.1 and all later versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt |
|
History
Wed, 26 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance. | |
| Title | Remote TCP DoS by throttling the TCP receive window | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-08-26T08:39:12.258Z
Reserved: 2026-08-05T07:36:55.457Z
Link: CVE-2026-18916
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T09:30:04Z
Weaknesses