THREAT OPS › Threat News › [NVD] CVE-2026-12969 (MEDIUM 5.3) — An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker cont
[NVD] CVE-2026-12969 (MEDIUM 5.3) — An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker cont
CVE-2026-12969 CVSS: 5.3 MEDIUM Published: 2026-06-23T14:17:22.790
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NX
Indicators of compromise
- CVE-2026-12969cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12969