Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 479
Alerts This Week
Warning Icon 1 479

Mageia dnsmasq Critical Denial of Service Vulnerabilities 2026-0288

mageia
Calendar Grey July 23, 2026
Scroller Mageia
A critical security advisory for Mageia addressing dnsmasq issues leading to potential denial of service attacks.
Mageia released updates for dnsmasq to fix critical security vulnerabilities, including a heap-based buffer overflow and an out-of-bounds read, potentially enabling remote denial o...

Summary

Description: The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969)

References

- https://bugs.mageia.org/show_bug.cgi?id=35935

- https://app.opencve.io/cve/CVE-2026-12725

- https://app.opencve.io/cve/CVE-2026-12969

- https://ubuntu.com/security/notices/USN-8542-1

- https://bugzilla.redhat.com/show_bug.cgi?id=2490763

- https://bugzilla.redhat.com/show_bug.cgi?id=2491663

- https://thekelleys.org.uk/dnsmasq/CHANGELOG

- https://www.cve.org/CVERecord?id=CVE-2026-12725

- https://www.cve.org/CVERecord?id=CVE-2026-12969

Resolution

SRPMS

- 10/core/dnsmasq-2.93-1.mga10

- 9/core/dnsmasq-2.93-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 23 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0288.html
Type: security
CVE: CVE-2026-12725, CVE-2026-12969

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.