Disclosed on May 11, 2026 (updated May 12, 2026)
PGV-2634742 is a category 3 vulnerabilty that affects debian/dnsmasq source, versions *, < 2.90-4~deb12u2, < 2.91-1+deb13u1, *
The risk assessment shows that this vulnerability is exlpoited by a external attacker. An unauthorized external actor who attempts to exploit this vulnerability without legitimate access.
The impact is contained to the application. Exploitation remains confined to the application and cannot affect the host environment or external systems.
The threat damage is caused by a data breach (limited). Exploitation does not provide access to data beyond what the user is already authorized to access.
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
| Network Exposure | External Accessable from the public internet |
| Access Interface | WebBrowser Primarily web-based applications |
| Service Outage | Disruptive Operations would be impacted |
| Data Breach | Disruptive Operations would be impacted |
| Data Tampering | Disruptive Operations would be impacted |
| Customize | |