THREAT OPS › Threat News › [NVD] CVE-2026-12725 (MEDIUM 5.9) — A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, logging of DS or DNSKEY replies containing
unsupported algorithm or digest types can cause dnsmasq to write past the end
of an internal logging buffer. A remote attacker
[NVD] CVE-2026-12725 (MEDIUM 5.9) — A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker
CVE-2026-12725 CVSS: 5.9 MEDIUM Published: 2026-06-22T16:16:34.490
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dns
Indicators of compromise
- CVE-2026-12725cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12725