Fedora Account System
Red Hat Associate
Red Hat Customer
The resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. An attacker controlling ANY DNSSEC-signed zone can craft NSEC records spanning into victim zones, enabling cross-zone cache poisoning with AD=1 (Authenticated Data flag set)