Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12725

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.22.1 (включая)
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
Версия до 2.93 (исключая)

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
redhat
4 месяца назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
msrc
около 2 месяцев назад

Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies

CVSS3: 5.9
debian
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...

CVSS3: 5.9
github
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-122