Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91164.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91164
Upstream
  • CVE-2026-12969
Published
2026-06-23T14:17:22Z
Modified
2026-08-28T17:48:12Z
Summary
CVE-2026-12969 affecting package dnsmasq for versions less than 2.93-1
Details

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.

References

Affected packages

Azure Linux:3 / dnsmasq

Package

Name
dnsmasq
Purl
pkg:rpm/azure-linux/dnsmasq

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.93-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91164.json"