CVE-2026-12725

Severity CVSS v4.0:
Pending analysis
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
22/06/2026
Last modified:
08/07/2026

Description

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and<br /> query logging are both enabled, logging of DS or DNSKEY replies containing<br /> unsupported algorithm or digest types can cause dnsmasq to write past the end<br /> of an internal logging buffer. A remote attacker able to supply such a DNS<br /> response may crash the dnsmasq process, resulting in denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* 4.0 (including) 4.22.1 (including)
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:* 2.93 (excluding)