An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade dnsmasq-utilsUpgrade dnsmasq | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade dnsmasq | May 15, 2026 | May 11, 2026 |
| Amazon Linux Ami 2 | — | Upgrade dnsmasq-debuginfoUpgrade dnsmasq-utilsUpgrade dnsmasq | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade dnsmasq-utils-debuginfoUpgrade dnsmasqUpgrade dnsmasq-debugsourceUpgrade dnsmasq-utilsUpgrade dnsmasq-debuginfo | May 28, 2026 | May 11, 2026 |
| Debian | — | Upgrade dnsmasq | May 12, 2026 | May 12, 2026 |
| Freebsd | — | Upgrade dnsmasqUpgrade dnsmasq-devel | May 13, 2026 | May 11, 2026 |
| Gentoo Linux | — | Upgrade net-dns/dnsmasq. | Aug 16, 2026 | Aug 13, 2026 |
| Oracle_linux | — | Upgrade dnsmasqUpgrade dnsmasq-utils | May 28, 2026 | May 11, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | May 9, 2026 |
| Redhat_linux | — | Upgrade dnsmasq-debugsourceUpgrade dnsmasq-debuginfoUpgrade dnsmasq-utilsUpgrade dnsmasqUpgrade dnsmasq-utils-debuginfoNo solution exists | May 20, 2026 | May 9, 2026 |
| Rocky_linux | — | Upgrade dnsmasq-utilsUpgrade dnsmasq-debuginfoUpgrade dnsmasq-debugsourceUpgrade dnsmasqUpgrade dnsmasq-utils-debuginfo | Jun 1, 2026 | May 29, 2026 |
| Suse | — | Upgrade dnsmasqUpgrade dnsmasq-utils | May 26, 2026 | May 18, 2026 |
| Ubuntu | — | Upgrade dnsmasqUpgrade dnsmasq (Ubuntu Pro) | May 25, 2026 | May 12, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 18, 2026 | May 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub