When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the comparison is done in 4 times a unsigned 32 bit number comparison, again with the endianness of the host where all values are actually in network bye order.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt |
|
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nlnetlabs
Nlnetlabs nsd |
|
| Vendors & Products |
Nlnetlabs
Nlnetlabs nsd |
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the comparison is done in 4 times a unsigned 32 bit number comparison, again with the endianness of the host where all values are actually in network bye order. | |
| Title | Wrong interpretation of ACL ranges | |
| Weaknesses | CWE-284 CWE-697 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NLnet Labs
Published: 2026-08-26T08:34:22.871Z
Updated: 2026-08-26T14:47:35.523Z
Reserved: 2026-08-03T13:23:02.012Z
Link: CVE-2026-18664
Updated: 2026-08-26T14:47:19.371Z
Status : Awaiting Analysis
Published: 2026-08-26T09:16:45.437
Modified: 2026-09-01T21:03:04.987
Link: CVE-2026-18664
No data.