Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12198

Опубликовано: 27 окт. 2025
Источник: redhat
CVSS3: 0

Описание

A heap-based buffer overflow vulnerability in dnsmasq within the parse_hex() function of src/util.c. When parsing malformed DHCP option values in configuration files, dnsmasq miscalculates the output length and writes beyond the allocated heap buffer. This can cause a crash (Denial of Service) and, in some cases, memory corruption that may enable arbitrary code execution. The flaw is triggered during configuration parsing, so an attacker who can supply or modify the dnsmasq configuration file could exploit it.

Отчет

This CVE has been marked as Rejected by the assigning CNA.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. To reduce the risk, restrict who can write or supply dnsmasq configuration files (ensure /etc/dnsmasq.conf and any included files are owned by root and not writable by unprivileged users), remove or avoid DHCP hex option entries coming from automated or untrusted sources, and validate configuration artifacts in your deployment pipeline before they reach production. Run dnsmasq with least privilege (drop root where possible, use systemd sandboxing, chroot or seccomp), enable runtime hardening (ASLR, hardened allocators) and monitor for crashes after config changes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dnsmasqNot affected
Red Hat Enterprise Linux 6dnsmasqFix deferred
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux 8dnsmasqNot affected
Red Hat Enterprise Linux 9dnsmasqNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2406466dnsmasq: dnsmasq Config File util.c parse_hex heap-based overflow

0 Low

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.

nvd
10 месяцев назад

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.

CVSS3: 7.8
github
10 месяцев назад

A vulnerability has been found in dnsmasq up to 2.73rc6. Affected is the function parse_hex of the file src/util.c of the component Config File Handler. The manipulation of the argument i leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0 Low

CVSS3