PatchSiren cyber security CVE debrief
CVE-2016-6173 Nlnetlabs CVE debrief
CVE-2016-6173 is a remote availability issue in NSD affecting versions before 4.1.11. According to NVD, a DNS master server can trigger denial of service on a slave server by sending a zone transfer with unlimited data, leading to /tmp disk consumption and a possible slave server crash. The published CVSS v3 vector rates this as network-reachable, low-complexity, no-authentication, and high availability impact.
- Vendor
- Nlnetlabs
- Product
- Nsd
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Operators and administrators running NSD slave servers, especially environments that receive zone transfers from remote master servers and still use versions 4.1.10 or earlier.
Technical summary
NVD identifies the affected CPE range as nlnetlabs:nsd through 4.1.10. The issue is classified as CWE-399 and has CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The documented failure mode is exhaustion of /tmp disk space and crash of the slave server during handling of an unbounded zone transfer. The official references include the NSD 4.1.11 release notes, issue tracking, and related mailing-list/vendor advisories.
Defensive priority
High. This is a remotely reachable denial-of-service condition with no required privileges or user interaction, and the primary impact is service availability.
Recommended defensive actions
- Upgrade NSD to 4.1.11 or later on all affected slave servers.
- Verify deployed NSD versions and compare them against the affected range through 4.1.10.
- Review zone-transfer handling and alerting so unexpected /tmp growth or NSD crashes are detected quickly.
- Confirm vendor release notes and related advisories before and after upgrading to ensure the fix is present in your packaged build.
Evidence notes
Supported by the NVD record and linked references in the provided corpus. The record states that NSD before 4.1.11 is vulnerable, lists the affected CPE range through 4.1.10, classifies the weakness as CWE-399, and assigns CVSS v3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The reference set includes the NSD 4.1.11 release notes, issue tracker entry, and related mailing-list/advisory links.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6173 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6173
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6173 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6173
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/sischkg/xfer-limit/blob/master/README.md
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015058.html
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://open.nlnetlabs.nl/pipermail/nsd-users/2016-August/002342.html
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.