Back

HIGH

dnsmasq: Improper bounds checking leads to a buffer overread

Published Aug 1, 2019

Description

Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.

Affected products

Remediation

Red Hat statement

This issue does not affect the versions of dnsmasq as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8. In Red Hat OpenStack Platform, which currently supports Red Hat Enterprise Linux 7.7, the dnsmasq package is pulled directly from the rhel-7-server-rpms channel. Red Hat OpenStack Platform is therefore unaffected, but please ensure that the underlying Red Hat Enterprise Linux dnsmasq package is current.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 1, 2019
Updated Aug 5, 2024
Reserved Aug 1, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 9, 2019