Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5172

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

A heap out-of-bounds read vulnerability was discovered in dnsmasq's DNS response processing. The extract_addresses() function trusts the declared record data length (rdlen) without verifying that a subsequent call to extract_name() stays within the record boundary. A crafted DNS response with a mismatched rdlen causes the remaining-bytes calculation to underflow, resulting in a massive out-of-bounds read and process crash.

Отчет

Red Hat rates this as Important. While this bug does not require any special dnsmasq configuration, the impact is limited to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dnsmasqOut of support scope
Red Hat Enterprise Linux 7dnsmasqNot affected
Red Hat Enterprise Linux 8dnsmasqWill not fix
Red Hat Enterprise Linux 9dnsmasqWill not fix
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10dnsmasqFixedRHSA-2026:1915819.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2458521dnsmasq: extract_addresses() OOB read via malformed rdlen

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

CVSS3: 7.3
nvd
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

CVSS3: 7.3
msrc
2 месяца назад

CVE-2026-5172

CVSS3: 7.3
debian
3 месяца назад

A buffer overflow in dnsmasq\u2019s extract_addresses() function allow ...

CVSS3: 7.3
github
3 месяца назад

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

7.5 High

CVSS3