CVE-2020-25687: vulnerability in dnsmasq
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A flaw in dnsmasq allows a remote attacker to crash the DNS service by sending specially crafted DNS replies when DNSSEC validation is enabled. This happens because the software doesn't properly check the length of data before copying it to memory.
A heap-based buffer overflow in dnsmasq's extract_name() function (rfc1035.c) occurs before DNSSEC validation, triggered by remote DNS replies with insufficient length checks. The vulnerability leads to negative-size memcpy() calls in sort_rrset(), causing a denial of service; exploitation requires the ability to craft valid DNS responses.