Hi Simon, On Mon, 2026-08-17 at 17:44 +0200, Salvatore Bonaccorso wrote: > Source: dnsmasq > Version: 2.93-1 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]> > > Hi, > > The following vulnerability was published for dnsmasq. > > Unfortunately at time of writing this bugreport only the Red Hat > bugzilla entry [1] was available. Can you check? > > CVE-2026-13002[0]: > > A flow has been identified into dnssec.c library, causing an > > infinite loop to dnsmasq service. An attacker who controls any > > DNSSEC-signed zone can hang the dnsmasq process with a single > > crafted response, killing all DNS resolution for its clients. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2026-13002 > https://www.cve.org/CVERecord?id=CVE-2026-13002 > [1] https://bugzilla.redhat.com/show_bug.cgi?id=2486360 > > Please adjust the affected versions in the BTS as needed.
do you know what might be causing the issue reported in the message quoted above? Unfortunately the bugreport at Red Hat is quite sparse. In case you have a patch available, I am happy to prepare uploads to unstable and trixie. Best, Sven -- GPG Fingerprint 3DF5 E8AA 43FC 9FDF D086 F195 ADF5 0EDA F8AD D585
signature.asc
Description: This is a digitally signed message part

