Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-12725

Опубликовано: 22 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.9

Описание

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

released

2.90-0ubuntu0.16.04.1+esm4
esm-infra/bionic

released

2.90-0ubuntu0.18.04.1+esm4
esm-infra/focal

released

2.90-0ubuntu0.20.04.1+esm3
jammy

released

2.90-0ubuntu0.22.04.4
noble

released

2.90-2ubuntu0.4
questing

ignored

end of life, was needs-triage
resolute

released

2.92-1ubuntu0.4
upstream

needs-triage

Показывать по

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
4 месяца назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
nvd
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

CVSS3: 5.9
msrc
около 2 месяцев назад

Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies

CVSS3: 5.9
debian
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...

CVSS3: 5.9
github
около 2 месяцев назад

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

EPSS

Процентиль: 33%
0.00403
Низкий

5.9 Medium

CVSS3