Critical Vulnerabilities in Fedora NSD: Access Control Bypass and DoS Risks

Critical Vulnerabilities in Fedora NSD: Access Control Bypass and DoS Risks

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Fedora released patches for multiple critical vulnerabilities in NSD, an authoritative DNS name server. The vulnerabilities include CVE-2026-18664, which allows IP range access control bypass, and CVE-2026-18916, enabling denial of service via TCP window throttling. Additionally, CVE-2026-19401 permits remote denial of service through crafted DNS Cookie options. CVE-2026-19538 allows access control bypass for users with proxy protocol port access. All vulnerabilities were published on August 26, 2026, and affect Fedora 43 and 44 versions. Users are urged to apply the patches immediately to mitigate risks. The updates can be installed using the 'dnf' update program.

Key Points: • Multiple critical vulnerabilities in Fedora NSD require immediate patching. • CVE-2026-18664 allows access control bypass; CVE-2026-18916 enables DoS attacks. • Patches are available for Fedora 43 and 44; users must update to secure their systems.

Ask AI about this cluster

Timeline

2026-08-26
CVE-2026-18664 published
Access control bypass due to incorrect IP range comparison reported by Palo Alto Networks.
Linuxsecurity
2026-08-26
CVE-2026-18916 published
Denial of service vulnerability via TCP receive window throttling disclosed.
Linuxsecurity
2026-08-26
CVE-2026-19401 published
Remote denial of service via crafted DNS Cookie options reported.
Linuxsecurity
2026-08-26
CVE-2026-19538 published
Access control bypass for users with proxy protocol port access disclosed.
Linuxsecurity
2026-09-08
Patches released for Fedora NSD
Fedora released updates addressing multiple critical vulnerabilities in NSD.
Linuxsecurity