A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dnsmasq | Sep 21, 2026 | Jun 22, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Apr 21, 2026 |
| Ubuntu | — | Upgrade dnsmasq-baseUpgrade dnsmasq-utilsUpgrade dnsmasq-base-luaUpgrade dnsmasq-utils (Ubuntu Pro)Upgrade dnsmasq (Ubuntu Pro)Upgrade dnsmasq-base-lua (Ubuntu Pro)Upgrade dnsmasqUpgrade dnsmasq-base (Ubuntu Pro) | Jul 15, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub