Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
Published Aug 14, 2026
4.4
MEDIUMCVSS 3.1
EPSS 0.15%
Description
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- 4.0
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
dnsmasq
Fix deferred
Red Hat Enterprise Linux 6
dnsmasq
Not affected
Red Hat Enterprise Linux 7
dnsmasq
Not affected
Red Hat Enterprise Linux 8
dnsmasq
Fix deferred
Red Hat Enterprise Linux 9
dnsmasq
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dnsmasq | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | dnsmasq | Not affected | n/a |
| Red Hat Enterprise Linux 7 | dnsmasq | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dnsmasq | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | dnsmasq | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Redhat confirms that the dnsmasq component is required for installations where DNNSEC service is in use.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.15% (0.00147) | 3.31th | v5 (v2026.06.15) |
| Aug 15, 2026 | 0.11% (0.00108) | 1.35th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-13002 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486360 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-13002
- https://www.cve.org/CVERecord?id=CVE-2026-13002
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-13002 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2486360 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-13002 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-13002 |
Change history (0)
No recorded changes yet.