Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5172

Опубликовано: 11 мая 2026
Источник: debian
EPSS Низкий

Описание

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.92-5package
dnsmasqnot-affectedbullseyepackage

Примечания

  • https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

  • https://xchglabs.com/blog/dnsmasq-five-cves.html

  • Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=073082ddc0aba7b8efa15a688d6183463b65effa (v2.93rc1)

  • Introduced with: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=638c7c4d20004c0f320820098e29df62a27dd2a1 (v2.90test1)

EPSS

Процентиль: 84%
0.02683
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

CVSS3: 7.5
redhat
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

CVSS3: 7.3
nvd
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

CVSS3: 7.3
msrc
2 месяца назад

CVE-2026-5172

CVSS3: 7.3
github
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

EPSS

Процентиль: 84%
0.02683
Низкий