Описание
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
A validation bypass was discovered in dnsmasq's RFC 7871 client subnet (ECS) handling. When verifying ECS source information in DNS responses, dnsmasq passes the OPT record length instead of the full packet length to the validation function.This causes all internal bounds checks to fail, completely bypassing ECS source validation and allowing an attacker to spoof client subnet information.
Отчет
Red Hat rates this as Moderate. This issue affects deployments with the --add-subnet option enabled. The impact is limited to bypassing ECS source validation, which could allow cache manipulation scoped to specific subnets or minor information disclosure about network topology.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | dnsmasq | Affected | ||
| Red Hat Enterprise Linux 7 | dnsmasq | Affected | ||
| Red Hat Enterprise Linux 10 | dnsmasq | Fixed | RHSA-2026:19158 | 19.05.2026 |
| Red Hat Enterprise Linux 8 | dnsmasq | Fixed | RHSA-2026:20589 | 26.05.2026 |
| Red Hat Enterprise Linux 9 | dnsmasq | Fixed | RHSA-2026:19373 | 19.05.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dnsmasq | Fixed | RHSA-2026:34508 | 01.07.2026 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607151909 | Fixed | RHSA-2026:40762 | 22.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
An information disclosure vulnerability in dnsmasq allows remote attac ...
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
EPSS
6.5 Medium
CVSS3