Bug 2524301 (CVE-2026-19538)

Summary: CVE-2026-19538 nsd: nsd: Access control bypass via repeated queries on proxy protocol port
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in nsd. A remote attacker can bypass BLOCKED access control list (ACL) items on the proxy protocol port. This bypass occurs when connecting over TCP or TLS and sending the query twice on a persistent connection. This could allow unauthorized access or actions that should have been prevented by the ACL.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2524357, 2524358    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-26 09:11:28 UTC
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.