CVE-2026-12725
Severity CVSS v4.0:
Pending analysis
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
22/06/2026
Last modified:
08/07/2026
Description
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and<br />
query logging are both enabled, logging of DS or DNSKEY replies containing<br />
unsupported algorithm or digest types can cause dnsmasq to write past the end<br />
of an internal logging buffer. A remote attacker able to supply such a DNS<br />
response may crash the dnsmasq process, resulting in denial of service.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* | 4.0 (including) | 4.22.1 (including) |
| cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:* | 2.93 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



