Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96617.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96617
Upstream
  • CVE-2026-13002
Published
2026-08-14T16:16:49Z
Modified
2026-09-03T05:27:10Z
Summary
CVE-2026-13002 affecting package dnsmasq 2.93-1
Details

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.

References

Affected packages

Azure Linux:3 / dnsmasq

Package

Name
dnsmasq
Purl
pkg:rpm/azure-linux/dnsmasq

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.93-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96617.json"