dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
August 13th, 2026
Vulnerability Details
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of NSEC records. The issue results from a lack of a proper exit condition in a loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Additional Details
Fixed in dnsmasq-2.93
Disclosure Timeline
- 2026-05-20 - Vulnerability reported to vendor
- 2026-08-13 - Coordinated public release of advisory
- 2026-08-13 - Advisory Updated
Credit
chwrld