Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian LTS: DLA-3974-1 critical: dnsmasq denial of service

debian lts
Calendar Grey November 30, 2024
Dist Debian Esm H88
Examine modifications for dnsmasq concerning urgent denial of service vulnerabilities in Debian LTS pertaining to releases 2.85-1.
Brief introduction CVE-2022-0934

Summary

Brief introduction

CVE-2022-0934

A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq.
This flaw allows an attacker who sends a crafted packet processed by
dnsmasq, potentially causing a denial of service.

CVE-2023-28450

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0
UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day
2020.

CVE-2023-50387

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840,
and related RFCs) allow remote attackers to cause a denial of service (CPU
consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One
of the concerns is that, when there is a zone with many DNSKEY and RRSIG
records, the protocol specification implies that an algorithm must evaluate
all combinations of DNSKEY and RRSIG records.

CVE-2023-50868

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: dnsmasq
Version: 2.85-1+deb11u1
CVE ID: CVE-2022-0934 CVE-2023-28450 CVE-2023-50387 CVE-2023-50868
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here