CVE-2026-6507 Details
Description
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).
An out-of-bounds write vulnerability has been identified in dnsmasq versions prior to 2.92. When a server is configured with the '--dhcp-split-relay' option, a remote attacker can send a specially crafted BOOTREPLY packet that exploits this vulnerability. The flaw occurs in the DHCP processing, where the dnsmasq server incorrectly handles the OPTION_AGENT_ID, leading to memory corruption. This corruption causes the dnsmasq daemon to crash, creating a denial-of-service condition.
To address this vulnerability, remove the '--dhcp-split-relay' option from the dnsmasq configuration. After making this change, restart the dnsmasq service to apply the new configuration. Be aware that this may temporarily disrupt DHCP and DNS services.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6507 | [email protected] | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2459181 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |