ZDI-CAN-30607: ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-584 - Compensating control
Mitigate the remote denial-of-service risk in dnsmasq (ZDI-26-584) since authentication is not required to exploit; restrict or protect external access to the dnsmasq service to reduce exposure.
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30607?
ZDI-CAN-30607 has a CVSS rating of 7.5, indicating a high severity level.
How do I fix ZDI-CAN-30607?
To mitigate ZDI-CAN-30607, update dnsmasq to the latest version provided by the vendor.
What type of vulnerability is ZDI-CAN-30607?
ZDI-CAN-30607 is a denial-of-service vulnerability that affects the dnsmasq software.
Can ZDI-CAN-30607 be exploited remotely?
Yes, ZDI-CAN-30607 can be exploited remotely without requiring authentication.
What impact does ZDI-CAN-30607 have on affected systems?
The impact of ZDI-CAN-30607 is that it can lead to an infinite loop, resulting in a denial-of-service condition.