ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
ZDI disclosed an unauthenticated infinite-loop denial-of-service flaw (CVE-2026-4890) in dnsmasq DNSSEC NSEC/NSEC3 bitmap processing.
The Zero Day Initiative published ZDI-26-584 describing an infinite loop in dnsmasq's processing of DNSSEC NSEC/NSEC3 type bitmaps. Remote unauthenticated attackers can trigger a denial-of-service condition on affected installations. ZDI assigned a CVSS score of 7.5 and the identifier CVE-2026-4890.
- Unauthenticated remote DoS via crafted NSEC/NSEC3 bitmaps
- No authentication required; CVSS 7.5
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-4890 | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. NVD description · AI analysis pending | 7.5 | 9% | — | — |
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.
This source does not provide full text. Read it at zerodayinitiative.com.