Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6507

Опубликовано: 17 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.92-4package
dnsmasqnot-affectedtrixiepackage
dnsmasqnot-affectedbookwormpackage
dnsmasqnot-affectedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2459181

  • Introduced with: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=1677c6e10b81d4e1181e3a3f88e738ea6d69be8a (v2.92test20)

  • Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=9ad74926d4f7f34ff902e1db5235535aa813c33f (v2.93test9)

EPSS

Процентиль: 39%
0.00482
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

CVSS3: 7.5
redhat
4 месяца назад

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

CVSS3: 7.5
nvd
4 месяца назад

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

msrc
3 месяца назад

Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing

CVSS3: 7.5
github
4 месяца назад

A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).

EPSS

Процентиль: 39%
0.00482
Низкий