CVE-2026-12725

EUVD-2026-38278
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, logging of DS or DNSKEY replies containing
unsupported algorithm or digest types can cause dnsmasq to write past the end
of an internal logging buffer. A remote attacker able to supply such a DNS
response may crash the dnsmasq process, resulting in denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.1%
Affected Products (NVD)
VendorProductVersion
redhatopenshift_container_platform
4.0 ≤
𝑥
≤ 4.22.1
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
thekelleysdnsmasq
𝑥
< 2.93
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dnsmasq
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
2.93-1
fixed
sid
2.93-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dnsmasq
bionic
Fixed 2.90-0ubuntu0.18.04.1+esm4
released
focal
Fixed 2.90-0ubuntu0.20.04.1+esm3
released
jammy
Fixed 2.90-0ubuntu0.22.04.4
released
noble
Fixed 2.90-2ubuntu0.4
released
questing
ignored
resolute
Fixed 2.92-1ubuntu0.4
released
trusty
not-affected
xenial
Fixed 2.90-0ubuntu0.16.04.1+esm4
released
Azure Linux logo
Azure Linux Releases
Azure Package
Release
dnsmasq
Azure Linux 3.0
0:2.93-1.azl3
fixed