CVE-2026-13002: Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13002?
The severity of CVE-2026-13002 is rated as medium with a score of 4.4.
How do I fix CVE-2026-13002?
To fix CVE-2026-13002, update the dnsmasq service to the latest patched version provided by your vendor.
What impact does CVE-2026-13002 have on systems?
CVE-2026-13002 can cause an infinite loop denial-of-service condition in the dnsmasq service, disrupting DNS resolution for clients.
Who can exploit CVE-2026-13002?
An attacker who controls any DNSSEC-signed zone can exploit CVE-2026-13002 with a crafted response.
Is there a workaround for CVE-2026-13002?
Currently, there are no official workarounds for CVE-2026-13002; updating the software is the recommended mitigation.