Disclosed on May 11, 2026 (updated May 12, 2026)
PGV-2634740 is a category 3 vulnerabilty that affects debian/dnsmasq source, versions *, < 2.90-4~deb12u2, < 2.91-1+deb13u1, *
The risk assessment shows that this vulnerability is exlpoited by a external attacker. An unauthorized external actor who attempts to exploit this vulnerability without legitimate access.
The impact is contained to the application. Exploitation remains confined to the application and cannot affect the host environment or external systems.
The threat damage is caused by a data breach (limited). Exploitation does not provide access to data beyond what the user is already authorized to access.
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
| Network Exposure | External Accessable from the public internet |
| Access Interface | WebBrowser Primarily web-based applications |
| Service Outage | Disruptive Operations would be impacted |
| Data Breach | Disruptive Operations would be impacted |
| Data Tampering | Disruptive Operations would be impacted |
| Customize | |