Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4893

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

A validation bypass was discovered in dnsmasq's RFC 7871 client subnet (ECS) handling. When verifying ECS source information in DNS responses, dnsmasq passes the OPT record length instead of the full packet length to the validation function.This causes all internal bounds checks to fail, completely bypassing ECS source validation and allowing an attacker to spoof client subnet information.

Отчет

Red Hat rates this as Moderate. This issue affects deployments with the --add-subnet option enabled. The impact is limited to bypassing ECS source validation, which could allow cache manipulation scoped to specific subnets or minor information disclosure about network topology.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqAffected
Red Hat Enterprise Linux 7dnsmasqAffected
Red Hat Enterprise Linux 10dnsmasqFixedRHSA-2026:1915819.05.2026
Red Hat Enterprise Linux 8dnsmasqFixedRHSA-2026:2058926.05.2026
Red Hat Enterprise Linux 9dnsmasqFixedRHSA-2026:1937319.05.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportdnsmasqFixedRHSA-2026:3450801.07.2026
Red Hat OpenShift Container Platform 4.19rhcos-4.19.9.6.202607151909FixedRHSA-2026:4076222.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2458519dnsmasq: Broken ECS source validation bypass

EPSS

Процентиль: 84%
0.02681
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

CVSS3: 5.3
nvd
3 месяца назад

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

CVSS3: 5.3
msrc
3 месяца назад

CVE-2026-4893

CVSS3: 5.3
debian
3 месяца назад

An information disclosure vulnerability in dnsmasq allows remote attac ...

CVSS3: 5.3
github
3 месяца назад

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

EPSS

Процентиль: 84%
0.02681
Низкий

6.5 Medium

CVSS3