Logo
vulnerabilityCVE-2026-12969
Name
CVE-2026-12969
Source
NVD ( link)Debian ( link)
Description
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dnsmasq
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.92rel2
Exploitable
buildroot
master
2.93
Not Affected
openwrt
master
2.93-r2
Not Affected
openwrt
openwrt-25.12
2.93-r1
Not Affected
yocto
master
2.93
Not Affected
yocto
scarthgap
2.90
Exploitable