Logo
vulnerabilityCVE-2026-12725
Name
CVE-2026-12725
Source
NVD ( link)Debian ( link)
Description
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dnsmasq
Exploitable

Vulnerability Ratings#


5.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.92rel2
Exploitable
buildroot
master
2.93
Not Affected
openwrt
master
2.93-r2
Not Affected
openwrt
openwrt-25.12
2.93-r1
Not Affected
yocto
master
2.93
Not Affected
yocto
scarthgap
2.90
Exploitable