CVE-2026-13002

Public on 2026-08-14
Modified on 2026-08-16
Description
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Dnsmasq Extra dnsmasq Pending Fix
Amazon Linux 2 - Core dnsmasq Not Affected
Amazon Linux 2 - Dnsmasq2.85 Extra dnsmasq No Fix Planned
Amazon Linux 2023 dnsmasq Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H