Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4891

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

A heap out-of-bounds read vulnerability was discovered in dnsmasq's DNSSEC validation. When processing RRSIG records, dnsmasq calculates the signature length by subtracting the fixed field size from the record's declared data length. A crafted RRSIG record with a data length smaller than the fixed fields causes this calculation to underflow, potentially resulting in an out-of-bounds read and process crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqWill not fix
Red Hat Enterprise Linux 7dnsmasqAffected
Red Hat Enterprise Linux 10dnsmasqFixedRHSA-2026:1915819.05.2026
Red Hat Enterprise Linux 8dnsmasqFixedRHSA-2026:2058926.05.2026
Red Hat Enterprise Linux 9dnsmasqFixedRHSA-2026:1937319.05.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportdnsmasqFixedRHSA-2026:3450801.07.2026
Red Hat OpenShift Container Platform 4.19rhcos-4.19.9.6.202607151909FixedRHSA-2026:4076222.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2458517dnsmasq: RRSIG rdlen underflow leading to heap OOB read

EPSS

Процентиль: 93%
0.06226
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

CVSS3: 5.3
nvd
3 месяца назад

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

CVSS3: 5.3
msrc
3 месяца назад

CVE-2026-4891

CVSS3: 5.3
debian
3 месяца назад

A heap-based out-of-bounds read vulnerability in the DNSSEC validation ...

CVSS3: 5.3
github
3 месяца назад

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

EPSS

Процентиль: 93%
0.06226
Низкий

7.5 High

CVSS3