NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNlnetlabs Bcder
APPNlnetlabs< 0.7.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2026-33278CRITICAL9.1PL ✓same vendor
Use-after-free w validatorze DNSSEC Unbound — RCE i DoS
CVE-2023-39916CRITICAL9.3PL ✓same vendor
Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem
CVE-2019-25035CRITICAL9.8PL ✓same vendor
Out-of-bounds write w Unbound przed wersją 1.9.5 (sldns_bget_token_par)
CVE-2019-25033CRITICAL9.8PL ✓same vendor
Integer overflow w Unbound przed wersją 1.9.5 (makro ALIGN_UP)
CVE-2019-25032CRITICAL9.8PL ✓same vendor
Integer overflow w alokatorze regionalnym Unbound DNS (przed wersją 1.9.5)