dnsmasq: heap overflow in the code responsible for building DNS replies
Published Oct 2, 2017
9.8
CRITICALCVSS 3.1
EPSS 84.92%
Description
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Affected products
No data.
Configuration 1
- ≤ 2.77
Configuration 2
- 6.0
- 7.0
- 6.0
- 7.0
- 6.0
- 7.0
Configuration 3
- 12.04
- 12.04
- 14.04
- 16.04
- 17.04
Configuration 4
- 7.0
- 7.1
- 8.0
- 9.0
Configuration 6
- 11
- 11
- 11
- 11
- 11
- 12
Configuration 7
- < r21.6
Running on/with
- n/a
Configuration 8
- < r24.2.2
Running on/with
- n/a
Configuration 9
- ≥ 3.0 · < 3.10.0.55
Configuration 10
- < jimmy-al00ac00b135
Running on/with
- n/a
Configuration 11
Configuration 12
- < 5.0
Running on/with
- n/a
Configuration 13
- < 5.0
Running on/with
- n/a
Configuration 14
- < 5.0
Running on/with
- n/a
Configuration 15
- < 6.5.1.5
Running on/with
- n/a
Configuration 16
- ≥ 6.3.1 · < 6.3.1.25
- ≥ 6.4.4.0 · < 6.4.4.16
- ≥ 6.5.0.0 · < 6.5.1.9
- ≥ 6.5.3.0 · < 6.5.3.3
- ≥ 6.5.4.0 · < 6.5.4.2
- ≥ 8.1.0.0 · < 8.1.0.4
Configuration 17
- 1.1
- 5.2
- 6.0
- 6.1
No data.
Red Hat Enterprise Linux 5 Extended Lifecycle Support
dnsmasq-0:2.45-2.el5_11.1
Fixed · RHSA-2017:2840
Red Hat Enterprise Linux 5.9 Long Life
dnsmasq-0:2.45-2.el5_9.1
Fixed · RHSA-2017:2841
Red Hat Enterprise Linux 6
dnsmasq-0:2.48-18.el6_9
Fixed · RHSA-2017:2838
Red Hat Enterprise Linux 6.2 Advanced Update Support
dnsmasq-0:2.48-5.el6_2.2
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.4 Advanced Update Support
dnsmasq-0:2.48-13.el6_4.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.5 Advanced Update Support
dnsmasq-0:2.48-13.el6_5.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.5 Telco Extended Update Support
dnsmasq-0:2.48-13.el6_5.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.6 Advanced Update Support
dnsmasq-0:2.48-14.el6_6.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
dnsmasq-0:2.48-14.el6_6.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 6.7 Extended Update Support
dnsmasq-0:2.48-16.el6_7.1
Fixed · RHSA-2017:2839
Red Hat Enterprise Linux 7
dnsmasq-0:2.76-2.el7_4.2
Fixed · RHSA-2017:2836
Red Hat Enterprise Linux 7.2 Extended Update Support
dnsmasq-0:2.66-14.el7_2.2
Fixed · RHSA-2017:2837
Red Hat Enterprise Linux 7.3 Extended Update Support
dnsmasq-0:2.66-21.el7_3.2
Fixed · RHSA-2017:2837
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
dnsmasq
Not affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
dnsmasq
Not affected
Red Hat OpenStack Platform 10 (Newton)
dnsmasq
Not affected
Red Hat OpenStack Platform 11 (Ocata)
dnsmasq
Not affected
Red Hat OpenStack Platform 12 (Pike)
dnsmasq
Not affected
Red Hat OpenStack Platform 8 (Liberty)
dnsmasq
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
dnsmasq
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | dnsmasq-0:2.45-2.el5_11.1 | Fixed | RHSA-2017:2840 |
| Red Hat Enterprise Linux 5.9 Long Life | dnsmasq-0:2.45-2.el5_9.1 | Fixed | RHSA-2017:2841 |
| Red Hat Enterprise Linux 6 | dnsmasq-0:2.48-18.el6_9 | Fixed | RHSA-2017:2838 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | dnsmasq-0:2.48-5.el6_2.2 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | dnsmasq-0:2.48-13.el6_4.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | dnsmasq-0:2.48-13.el6_5.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | dnsmasq-0:2.48-13.el6_5.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | dnsmasq-0:2.48-14.el6_6.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | dnsmasq-0:2.48-14.el6_6.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | dnsmasq-0:2.48-16.el6_7.1 | Fixed | RHSA-2017:2839 |
| Red Hat Enterprise Linux 7 | dnsmasq-0:2.76-2.el7_4.2 | Fixed | RHSA-2017:2836 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | dnsmasq-0:2.66-14.el7_2.2 | Fixed | RHSA-2017:2837 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | dnsmasq-0:2.66-21.el7_3.2 | Fixed | RHSA-2017:2837 |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | dnsmasq | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | dnsmasq | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | dnsmasq | Not affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | dnsmasq | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | dnsmasq | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | dnsmasq | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | dnsmasq | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform includes the dnsmasq-utils RPM which does not contain this flaw's affected code-paths; Red Hat OpenStack Platform is therefore listed as not affected. However, because all versions of Red Hat OpenStack Platform are based on Red Hat Enterprise Linux, all Red Hat OpenStack Platform users should absolutely upgrade the dnsmasq RPM from Red Hat Enterprise Linux as a matter of urgency using standard update mechanisms (such as 'yum update' or 'openstack overcloud update').
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (65 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 84.92% (0.84925) | 99.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 84.92% (0.84925) | 99.68th | v5 (v2026.06.15) |
| May 28, 2026 | 33.72% (0.33720) | 97.03th | v4 (v2025.03.14) |
| May 13, 2026 | 49.79% (0.49785) | 97.84th | v4 (v2025.03.14) |
| Apr 12, 2026 | 57.79% (0.57794) | 98.18th | v4 (v2025.03.14) |
| Mar 25, 2026 | 62.66% (0.62655) | 98.35th | v4 (v2025.03.14) |
| Mar 4, 2026 | 60.19% (0.60192) | 98.23th | v4 (v2025.03.14) |
| Mar 1, 2026 | 39.89% (0.39886) | 97.27th | v4 (v2025.03.14) |
| Feb 4, 2026 | 60.19% (0.60192) | 98.21th | v4 (v2025.03.14) |
| Feb 1, 2026 | 39.89% (0.39886) | 97.23th | v4 (v2025.03.14) |
| Jan 4, 2026 | 60.19% (0.60192) | 98.19th | v4 (v2025.03.14) |
| Jan 1, 2026 | 39.89% (0.39886) | 97.21th | v4 (v2025.03.14) |
| Dec 28, 2025 | 60.19% (0.60192) | 98.18th | v4 (v2025.03.14) |
| Dec 27, 2025 | 52.38% (0.52378) | 97.83th | v4 (v2025.03.14) |
| Dec 4, 2025 | 60.19% (0.60192) | 98.17th | v4 (v2025.03.14) |
| Dec 1, 2025 | 39.89% (0.39886) | 97.17th | v4 (v2025.03.14) |
| Nov 4, 2025 | 60.19% (0.60192) | 98.17th | v4 (v2025.03.14) |
| Nov 1, 2025 | 39.89% (0.39886) | 97.16th | v4 (v2025.03.14) |
| Oct 28, 2025 | 60.19% (0.60192) | 98.17th | v4 (v2025.03.14) |
| Oct 27, 2025 | 52.38% (0.52378) | 97.79th | v4 (v2025.03.14) |
| Oct 4, 2025 | 60.19% (0.60192) | 98.21th | v4 (v2025.03.14) |
| Oct 1, 2025 | 39.89% (0.39886) | 97.23th | v4 (v2025.03.14) |
| Sep 5, 2025 | 52.38% (0.52378) | 97.84th | v4 (v2025.03.14) |
| Sep 1, 2025 | 39.89% (0.39886) | 97.24th | v4 (v2025.03.14) |
| Aug 5, 2025 | 52.38% (0.52378) | 97.81th | v4 (v2025.03.14) |
| Aug 1, 2025 | 39.89% (0.39886) | 97.21th | v4 (v2025.03.14) |
| Jul 4, 2025 | 52.38% (0.52378) | 97.78th | v4 (v2025.03.14) |
| Jul 1, 2025 | 39.89% (0.39886) | 97.17th | v4 (v2025.03.14) |
| Jun 4, 2025 | 52.38% (0.52378) | 97.76th | v4 (v2025.03.14) |
| Jun 1, 2025 | 39.89% (0.39886) | 97.16th | v4 (v2025.03.14) |
| May 4, 2025 | 52.38% (0.52378) | 97.76th | v4 (v2025.03.14) |
| May 1, 2025 | 39.89% (0.39886) | 97.12th | v4 (v2025.03.14) |
| Apr 23, 2025 | 52.38% (0.52378) | 97.74th | v4 (v2025.03.14) |
| Apr 22, 2025 | 69.85% (0.69848) | 98.54th | v4 (v2025.03.14) |
| Apr 17, 2025 | 66.59% (0.66588) | 98.40th | v4 (v2025.03.14) |
| Apr 15, 2025 | 70.65% (0.70651) | 98.57th | v4 (v2025.03.14) |
| Mar 31, 2025 | 68.61% (0.68612) | 98.50th | v4 (v2025.03.14) |
| Mar 30, 2025 | 61.85% (0.61851) | 98.19th | v4 (v2025.03.14) |
| Mar 29, 2025 | 54.60% (0.54603) | 97.14th | v4 (v2025.03.14) |
| Mar 28, 2025 | 68.61% (0.68612) | 98.50th | v4 (v2025.03.14) |
| Mar 27, 2025 | 72.21% (0.72214) | 98.62th | v4 (v2025.03.14) |
| Mar 22, 2025 | 68.61% (0.68612) | 98.55th | v4 (v2025.03.14) |
| Mar 21, 2025 | 61.85% (0.61851) | 98.22th | v4 (v2025.03.14) |
| Mar 20, 2025 | 68.61% (0.68612) | 98.55th | v4 (v2025.03.14) |
| Mar 19, 2025 | 72.21% (0.72214) | 98.65th | v4 (v2025.03.14) |
| Mar 18, 2025 | 61.85% (0.61851) | 98.19th | v4 (v2025.03.14) |
| Mar 17, 2025 | 68.61% (0.68612) | 98.51th | v4 (v2025.03.14) |
| Dec 17, 2024 | 54.35% (0.54353) | 97.75th | v3 (v2023.03.01) |
| Aug 13, 2024 | 30.29% (0.30287) | 97.01th | v3 (v2023.03.01) |
| Aug 10, 2024 | 34.29% (0.34286) | 97.15th | v3 (v2023.03.01) |
| May 5, 2024 | 30.29% (0.30287) | 96.91th | v3 (v2023.03.01) |
| Nov 28, 2023 | 33.26% (0.33262) | 96.62th | v3 (v2023.03.01) |
| Nov 8, 2023 | 35.70% (0.35696) | 96.71th | v3 (v2023.03.01) |
| Oct 18, 2023 | 31.32% (0.31323) | 96.46th | v3 (v2023.03.01) |
| Sep 12, 2023 | 33.55% (0.33551) | 96.50th | v3 (v2023.03.01) |
| Aug 12, 2023 | 37.69% (0.37685) | 96.70th | v3 (v2023.03.01) |
| May 8, 2023 | 45.66% (0.45658) | 96.85th | v3 (v2023.03.01) |
| Mar 16, 2023 | 34.53% (0.34528) | 96.40th | v3 (v2023.03.01) |
| Mar 7, 2023 | 36.44% (0.36444) | 96.49th | v3 (v2023.03.01) |
| Mar 6, 2023 | 78.09% (0.78085) | 99.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 78.09% (0.78085) | 99.32th | v2 (v2022.01.01) |
| Feb 3, 2022 | 52.06% (0.52056) | 99.07th | v1 |
| Nov 9, 2021 | 52.06% (0.52056) | 99.68th | v1 |
| Sep 1, 2021 | 41.62% (0.41618) | 99.29th | v1 |
| Apr 14, 2021 | 41.62% (0.41618) | 0.00th | v1 |
References (43)
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4560 x_refsource_CONFIRMThird Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561 x_refsource_CONFIRMThird Party Advisory
- http://packetstormsecurity.com/files/144480/Dnsmasq-2-Byte-Heap-Based-Overflow.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://thekelleys.org.uk/dnsmasq/CHANGELOG x_refsource_CONFIRMRelease NotesVendor Advisory
- http://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=0549c73b7ea6b22a3c49beb4d432f185a81efcbc x_refsource_CONFIRM
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-005.txt x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2017/dsa-3989 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171103-01-dnsmasq-en x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/101085 vdb-entryx_refsource_BIDBroken Link
- http://www.securityfocus.com/bid/101977 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id/1039474 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.ubuntu.com/usn/USN-3430-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-3430-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-3430-3 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2836 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2837 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2838 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2839 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2840 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2841 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-14491 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/3199382 x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1495409 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-689071.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/527KNN34RN2SB6MBJG7CKSEBWYE3TJEB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MMPCJOYPPL4B5RBY4U425PWG7EETDTD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXRZ2W6TV6NLUJC5NOFBSG6PZSMDTYPV/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2017-14491
- https://security.gentoo.org/glsa/201710-27 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html x_refsource_MISCThird Party Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/3577-security-advisory-30 x_refsource_MISCMitigationThird Party Advisory
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-449 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-14491
- https://www.debian.org/security/2017/dsa-3989 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.exploit-db.com/exploits/42941/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/973527 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11664.html mailing-listx_refsource_MLIST
- https://www.mail-archive.com/dnsmasq-discuss%40lists.thekelleys.org.uk/msg11665.html mailing-listx_refsource_MLIST
- https://www.synology.com/support/security/Synology_SA_17_59_Dnsmasq x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.