A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade dnsmasqUpgrade dnsmasq-debuginfoUpgrade dnsmasq-utils | Aug 7, 2020 | Aug 7, 2020 |
| Debian | — | Upgrade dnsmasq | Jul 30, 2024 | Feb 6, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade dnsmasq | Nov 3, 2022 | Feb 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade dnsmasq-utilsUpgrade dnsmasq | Mar 13, 2024 | Feb 6, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade dnsmasq | Nov 15, 2022 | Feb 6, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 6, 2021 |
| Suse | — | Upgrade dnsmasq-utilsUpgrade dnsmasq | Oct 28, 2021 | Feb 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub