Описание
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
A heap buffer overflow was discovered in dnsmasq's DHCP script helper process. When processing DHCPv6 client identifiers (CLIDs), the helper hex-encodes the raw CLID bytes into a fixed-size buffer without length validation. Since DHCPv6 CLIDs can be up to 65,535 bytes, a crafted DHCPv6 packet can overflow the buffer with attacker-controlled content. The helper process runs with root privileges.
Отчет
Red Hat rates this as Important. The overflow occurs in a root-privileged helper process with attacker-controlled content, and the --dhcp-script option is enabled by default in libvirt virtual network configurations, which affects RHEL systems using virt-manager, virt-install, or cockpit-machines. Exploitation requires the attacker to send crafted DHCPv6 packets from within the virtual network, meaning a malicious VM guest could potentially exploit this for host-level code execution as root.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | dnsmasq | Will not fix | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Affected | ||
| Red Hat Enterprise Linux 10 | dnsmasq | Fixed | RHSA-2026:19158 | 19.05.2026 |
| Red Hat Enterprise Linux 8 | dnsmasq | Fixed | RHSA-2026:20589 | 26.05.2026 |
| Red Hat Enterprise Linux 9 | dnsmasq | Fixed | RHSA-2026:19373 | 19.05.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dnsmasq | Fixed | RHSA-2026:34508 | 01.07.2026 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607151909 | Fixed | RHSA-2026:40762 | 22.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
A heap-based out-of-bounds write vulnerability in the DHCPv6 implement ...
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
EPSS
8.8 High
CVSS3