CVE-2026-30871: OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query

Published Mar 19, 2026
·
Updated

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parsequestion function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dnexpand into an 8096-byte global buffer (namebuffer), which is then copied via an unbounded strcpy into a fixed 256-byte stack buffer when handling TYPEPTR queries. The overflow is possible because dnexpand converts non-printable ASCII bytes (e.g., 0x01) into multi-character octal representations (e.g., \001), significantly inflating the expanded name beyond the stack buffer's capacity. A crafted DNS packet can exploit this expansion behavior to overflow the stack buffer, making the vulnerability reachable through normal multicast DNS packet processing. This issue has been fixed in versions 24.10.6 and 25.12.1.

Affected Software

3 affected components
OpenWrt Project OpenWrt<24.10.6, <25.12.1
OpenWrt OpenWrt<24.10.6
OpenWrt OpenWrt>=25.12.0<25.12.1

Event History

Mar 19, 2026
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-30871?

CVE-2026-30871 has a high severity rating due to the potential for remote code execution through a stack-based buffer overflow.

2

How do I fix CVE-2026-30871?

To fix CVE-2026-30871, upgrade your OpenWrt installation to version 24.10.6 or 25.12.1 or later.

3

What versions of OpenWrt are affected by CVE-2026-30871?

CVE-2026-30871 affects OpenWrt versions prior to 24.10.6 and 25.12.1.

4

What component of OpenWrt is vulnerable in CVE-2026-30871?

The mdns daemon is the vulnerable component in OpenWrt affected by CVE-2026-30871.

5

What trigger causes CVE-2026-30871 to occur?

CVE-2026-30871 is triggered by a malformed DNS PTR query leading to stack-based buffer overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203