MGASA-2026-0288

Source
https://advisories.mageia.org/MGASA-2026-0288.html
Import Source
https://advisories.mageia.org/MGASA-2026-0288.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0288
Upstream
  • CVE-2026-12725
  • CVE-2026-12969
Published
2026-07-23T17:45:56Z
Modified
2026-07-23T18:00:05.436377194Z
Summary
Updated dnsmasq packages fix security vulnerabilities
Details

The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's findsoa() function in src/rfc1035.c. When parsing NS section records, extractname() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969)

References
Credits

Affected packages

Mageia:10 / dnsmasq

Package

Name
dnsmasq
Purl
pkg:rpm/mageia/dnsmasq?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.93-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0288.json"

Mageia:9 / dnsmasq

Package

Name
dnsmasq
Purl
pkg:rpm/mageia/dnsmasq?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.93-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0288.json"