The vendor explicitly states that these products are not affected by this CVE.
- dnsmasq as a component of Red Hat Enterprise Linux 10
- dnsmasq-utils as a component of Red Hat Enterprise Linux 10
- dnsmasq.src as a component of Red Hat Enterprise Linux 10
- dnsmasq as a component of Red Hat Enterprise Linux 6
- dnsmasq-utils as a component of Red Hat Enterprise Linux 6
- dnsmasq.src as a component of Red Hat Enterprise Linux 6
- dnsmasq as a component of Red Hat Enterprise Linux 7
- dnsmasq-utils as a component of Red Hat Enterprise Linux 7
- dnsmasq.src as a component of Red Hat Enterprise Linux 7
- dnsmasq as a component of Red Hat Enterprise Linux 8
- dnsmasq-utils as a component of Red Hat Enterprise Linux 8
- dnsmasq.src as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).
- Remediation
- No remediation text is recorded.
