Executive brief
dnsmasq is a widely used networking tool that provides DNS and DHCP services for home routers and small corporate networks. A security flaw has been identified that allows remote attackers to bypass certain source-address checks by sending specially crafted DNS packets. This could lead to the unauthorized disclosure of internal network information or allow attackers to manipulate how DNS responses are routed, potentially facilitating further attacks.
Technical details
An information disclosure vulnerability exists in dnsmasq due to improper handling of EDNS0 Client Subnet (ECS) options as defined in RFC 7871. By crafting a DNS packet containing specific client-subnet information, a remote, unauthenticated attacker can bypass source-address validation checks. This flaw can be exploited to leak internal network information or manipulate response routing, which may assist in DNS cache poisoning or redirection attacks. The vulnerability is addressed in dnsmasq version 2.92rel2.
Affected products
- Simon Kelley dnsmasq versions prior to 2.92rel2
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory
- 2026-05-11: patched: Fixed in version 2.92rel2