Vulnerability Description
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | >= 4.0, <= 4.22.1 |
| Redhat | Enterprise Linux | 8.0 |
| Thekelleys | Dnsmasq | < 2.93 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-12725MitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2490763Issue TrackingVendor Advisory
FAQ
What is CVE-2026-12725?
CVE-2026-12725 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause...
How severe is CVE-2026-12725?
CVE-2026-12725 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12725?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift Container Platform, Redhat Enterprise Linux, Thekelleys Dnsmasq.