ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability

mediumVulnerabilityimportance 30CVE-2026-4890
AI summary · glm-5.3-flash

ZDI disclosed an unauthenticated infinite-loop denial-of-service flaw (CVE-2026-4890) in dnsmasq DNSSEC NSEC/NSEC3 bitmap processing.

The Zero Day Initiative published ZDI-26-584 describing an infinite loop in dnsmasq's processing of DNSSEC NSEC/NSEC3 type bitmaps. Remote unauthenticated attackers can trigger a denial-of-service condition on affected installations. ZDI assigned a CVSS score of 7.5 and the identifier CVE-2026-4890.

  • Unauthenticated remote DoS via crafted NSEC/NSEC3 bitmaps
  • No authentication required; CVSS 7.5

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-4890
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

NVD description · AI analysis pending
7.59%
Full article

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.

This source does not provide full text. Read it at zerodayinitiative.com.