PT-2026-81985 · Nlnet+4 · Nsd
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NSD (affected versions not specified)
Description
On little-endian systems, the software incorrectly compares IP addresses with access control ranges. This occurs because IPv4 addresses are compared as unsigned 32-bit numbers using the host's endianness, while the comparison values remain in network byte order (big-endian). For IPv6 addresses, the process involves four separate unsigned 32-bit number comparisons, also failing to account for the difference between host endianness and network byte order. Consequently, IP addresses intended to be allowed may be denied, and those intended to be denied may be granted access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nsd