CVE-2026-13002

EUVD-2026-58674
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.28%
Affected Products (NVD)
VendorProductVersion
redhatopenshift_container_platform
4.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dnsmasq
bookworm
postponed
bookworm (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dnsmasq
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
resolute
deferred
trusty
deferred
xenial
deferred
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
dnsmasq
Amazon Linux 2023
0:2.90-1.amzn2023.0.3
fixed
dnsmasq-debuginfo
Amazon Linux 2023
0:2.90-1.amzn2023.0.3
fixed
dnsmasq-debugsource
Amazon Linux 2023
0:2.90-1.amzn2023.0.3
fixed
dnsmasq-utils
Amazon Linux 2023
0:2.90-1.amzn2023.0.3
fixed
dnsmasq-utils-debuginfo
Amazon Linux 2023
0:2.90-1.amzn2023.0.3
fixed