CVE-2026-6507: Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the --dhcp-split-relay option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).
Other sources
On dnsmasq 2.92, a server-facing BOOTREPLY processed under --dhcp-split-relay can place OPTIONAGENTID at the end of a 552-byte packet and make dnsmasq zero one byte past the receive buffer. In my PoC, a benign 552-byte BOOTREPLY leaves the daemon alive, while the malicious variant followed by one oversized BOOTREPLY aborts the normal build with malloc(): invalid next size (unsorted). The attached PoC also reproduces the direct AddressSanitizer report at src/rfc2131.c:3251.
Details The bug is in src/rfc2131.c:3249-3251. After finding OPTIONAGENTID, dnsmasq sets opt = OPTIONEND and then executes memset(opt + 1, 0, optionlen(opt) + 2). The attached PoC uses the smallest RFC 3046-conformant Agent Information option: OPTIONAGENTID, length 2, followed by one zero-length sub-option (01 00). When that option starts at byte 548 of a 552-byte BOOTREPLY, memset(opt + 1, 0, 4) clears bytes 549..552, so the last byte is still written one byte past the end of the packet buffer. The buffer is exact-size because recvdhcppacket() grows the receive iovec to the packet length in src/dhcp-common.c:54-64, and expandbuf() reallocates that exact size in src/util.c:703-716.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/dnsmasqto a version that resolves this vulnerability.Fixed in 2.85-1Fixed in 2.85-1+deb11u1Fixed in 2.90-4~deb12u2Fixed in 2.91-1+deb13u1Fixed in 2.92-5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6507?
CVE-2026-6507 has been classified as a denial of service vulnerability.
How do I fix CVE-2026-6507?
To fix CVE-2026-6507, update Dnsmasq to version 2.93 or later.
What is the impact of CVE-2026-6507?
The impact of CVE-2026-6507 is that it allows a remote attacker to cause a denial of service on the Dnsmasq server.
Which versions of Dnsmasq are affected by CVE-2026-6507?
CVE-2026-6507 affects Dnsmasq version 2.92.
Can CVE-2026-6507 be exploited remotely?
Yes, CVE-2026-6507 can be exploited remotely by sending a specially crafted BOOTREPLY packet.