CVE-2020-25681: vulnerability in dnsmasq
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Dnsmasq has a heap memory overflow vulnerability when processing DNS responses with DNSSEC validation. An attacker can exploit this by sending specially crafted DNS replies to potentially run malicious code or crash the system.
A heap-based buffer overflow exists in RRSet sorting during DNSSEC validation in dnsmasq < 2.83. An attacker with network access capable of forging DNS replies can trigger arbitrary heap memory corruption, potentially achieving code execution or denial of service. Requires the victim to accept the forged DNS response as valid.