CVE-2022-0934: Use After Free
A flaw was found in dnsmasq. A heap use after free issue in the dhcp6 server may lead to remote denial of service via crafted packet.
References:
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2022q1/016272.html
Other sources
A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0934?
CVE-2022-0934 is a single-byte non-arbitrary write/use-after-free flaw found in dnsmasq.
What is the severity of CVE-2022-0934?
The severity of CVE-2022-0934 is high, with a CVSS score of 7.5.
What is the affected software?
The affected software includes Thekelleys Dnsmasq and Redhat Enterprise Linux 8.0 and 9.0.
How does CVE-2022-0934 impact the systems?
CVE-2022-0934 could potentially cause a denial of service if an attacker sends a crafted packet processed by dnsmasq.
Are there any references for CVE-2022-0934?
Yes, you can find more information about CVE-2022-0934 at the following references: [link 1](https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2022q1/016272.html), [link 2](https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=03345ecefeb0d82e3c3a4c28f27c3554f0611b39), [link 3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0934).