Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Description:
The updated dnsmasq packages fix multiple security issues:
A heap-based buffer overflow was found in dnsmasq. When DNSSEC
validation and query logging are both enabled, logging of DS or DNSKEY
replies containing unsupported algorithm or digest types can cause
dnsmasq to write past the end of an internal logging buffer.
A remote attacker able to supply such a DNS response may crash the
dnsmasq process, resulting in denial of service. (CVE-2026-12725)
An out-of-bounds read vulnerability exists in dnsmasq's find_soa()
function in src/rfc1035.c. When parsing NS section records,
extract_name() is called with extrabytes=0, failing to validate that 10
additional bytes exist for fixed-length DNS record fields. A remote
attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN
response to cause a 10-byte heap out-of-bounds read, potentially
accessing stale data from prior transactions. (CVE-2026-12969)
- https://bugs.mageia.org/show_bug.cgi?id=35935
- https://app.opencve.io/cve/CVE-2026-12725
- https://app.opencve.io/cve/CVE-2026-12969
- https://ubuntu.com/security/notices/USN-8542-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2490763
- https://bugzilla.redhat.com/show_bug.cgi?id=2491663
- https://thekelleys.org.uk/dnsmasq/CHANGELOG
- https://www.cve.org/CVERecord?id=CVE-2026-12725
- https://www.cve.org/CVERecord?id=CVE-2026-12969
- 10/core/dnsmasq-2.93-1.mga10
- 9/core/dnsmasq-2.93-1.mga9
Publication date:23 Jul 2026
Get the latest Linux and open source security news straight to your inbox.