Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4890

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

A denial of service vulnerability was discovered in dnsmasq's DNSSEC validation. When parsing NSEC and NSEC3 bitmap records, the window iteration logic fails to account for the 2-byte window header when advancing through the bitmap data. A specially crafted DNS response with a zero-length bitmap can cause an infinite loop, making dnsmasq unresponsive to all queries.

Отчет

This issue affects deployments with DNSSEC validation enabled (--dnssec). The flaw is reachable before RRSIG signature validation, meaning no valid DNSSEC signatures are required to trigger it. However, the primary impact is limited to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqUnder investigation
Red Hat Enterprise Linux 7dnsmasqUnder investigation
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Enterprise Linux 10dnsmasqFixedRHSA-2026:1915819.05.2026
Red Hat Enterprise Linux 8dnsmasqFixedRHSA-2026:2058926.05.2026
Red Hat Enterprise Linux 9dnsmasqFixedRHSA-2026:1937319.05.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportdnsmasqFixedRHSA-2026:3450801.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2458516dnsmasq: NSEC bitmap parsing infinite loop

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

CVSS3: 7.5
nvd
3 месяца назад

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

CVSS3: 7.5
msrc
3 месяца назад

CVE-2026-4890

CVSS3: 7.5
debian
3 месяца назад

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dn ...

CVSS3: 7.5
github
3 месяца назад

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

7.5 High

CVSS3