Input validation error in Dnsmasq - CVE-2026-4890
Published: May 12, 2026
Dnsmasq
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in NSEC bitmap parsing in dnssec.c when processing crafted DNSSEC NSEC or NSEC3 records. A remote attacker can send a specially crafted DNS response to cause a denial of service.
No valid DNSSEC signatures are needed because the issue is reachable before RRSIG validation.