dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability

August 13th, 2026

Vulnerability Details

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of NSEC records. The issue results from a lack of a proper exit condition in a loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

Additional Details

Fixed in dnsmasq-2.93


Disclosure Timeline

  • 2026-05-20 - Vulnerability reported to vendor
  • 2026-08-13 - Coordinated public release of advisory
  • 2026-08-13 - Advisory Updated

Credit

chwrld

Back to Advisories