CVE-2026-5172

Public on 2026-05-11
Modified on 2026-05-14
Description
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core dnsmasq Not Affected
Amazon Linux 2 - Dnsmasq Extra dnsmasq 2026-05-26 ALAS2DNSMASQ-2026-004 Fixed
Amazon Linux 2023 dnsmasq 2026-05-26 ALAS2023-2026-1729 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H