Описание
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
A heap out-of-bounds read vulnerability was discovered in dnsmasq's DNSSEC validation. When processing RRSIG records, dnsmasq calculates the signature length by subtracting the fixed field size from the record's declared data length. A crafted RRSIG record with a data length smaller than the fixed fields causes this calculation to underflow, potentially resulting in an out-of-bounds read and process crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | dnsmasq | Will not fix | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Affected | ||
| Red Hat Enterprise Linux 10 | dnsmasq | Fixed | RHSA-2026:19158 | 19.05.2026 |
| Red Hat Enterprise Linux 8 | dnsmasq | Fixed | RHSA-2026:20589 | 26.05.2026 |
| Red Hat Enterprise Linux 9 | dnsmasq | Fixed | RHSA-2026:19373 | 19.05.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dnsmasq | Fixed | RHSA-2026:34508 | 01.07.2026 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607151909 | Fixed | RHSA-2026:40762 | 22.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
A heap-based out-of-bounds read vulnerability in the DNSSEC validation ...
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
EPSS
7.5 High
CVSS3