Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12725

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

Отчет

Red Hat Product Security rates this issue as Moderate. The overflow occurs in the query logging path only, requires both DNSSEC validation and query logging to be enabled, involves a bounded overwrite with non-attacker-controlled data, and is most appropriately characterized as a denial of service rather than a confidentiality, integrity, or code execution issue. This assessment is consistent with the upstream maintainer's analysis.

Меры по смягчению последствий

Mitigate this issue by updating to a version of dnsmasq that includes the upstream fix (commit 36d081e37477027fd721fea498f3760f529034ad), or by disabling query logging if DNSSEC validation must remain enabled. After changing the configuration, restart the dnsmasq service for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dnsmasqFix deferred
Red Hat Enterprise Linux 6dnsmasqNot affected
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux 8dnsmasqFix deferred
Red Hat Enterprise Linux 9dnsmasqFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2490763dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported DS/DNSKEY replies

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
nvd
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
msrc
около 2 месяцев назад

Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies

CVSS3: 5.9
debian
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...

CVSS3: 5.9
github
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3