<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:53:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03623</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03623</link>
      <description>bdu:2021-03623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03623</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-25685 — CVE-2020-25685 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-25685</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-25685</guid>
    </item>
    <item>
      <title>certfr-2021-avi-041 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-041</link>
      <description>certfr-2021-avi-041</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-041</guid>
    </item>
    <item>
      <title>cisco-sa-dnsmasq-dns-2021-c5mrdf3g — Multiple Vulnerabilities in dnsmasq DNS Forwarder Affecting Cisco Products: January 2021</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-dnsmasq-dns-2021-c5mrdf3g</link>
      <description>&lt;p&gt;A set of previously unknown vulnerabilities in the DNS forwarder implementation of dnsmasq were disclosed on January 19, 2021. The vulnerabilities are collectively known as DNSpooq.&#13;
&#13;
Exploitation of these vulnerabilities could result in remote code execution or denial of service (DoS), or may allow an attacker to more easily forge DNS answers that can poison DNS caches, depending on the specific vulnerability.&#13;
&#13;
Multiple Cisco products are affected by these vulnerabilities.&#13;
&#13;
Cisco will release software updates that address these vulnerabilities. Any workarounds for a specific Cisco product or service will be documented in the relevant Cisco bugs, which are identified in the Vulnerable Products [&amp;#34;#vp&amp;#34;] section of this advisory.&#13;
&#13;
Note: At the time of publication, no Cisco products were found to be affected by the remote code execution and DoS vulnerabilities, which are identified by the following Common Vulnerabilities and Exposures (CVE) IDs:&#13;
&#13;
&#13;
CVE-2020-25681&#13;
CVE-2020-25682&#13;
CVE-2020-25683&#13;
CVE-2020-25687&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A set of previously unknown vulnerabilities in the DNS forwarder implementation of dnsmasq were disclosed on January 19, 2021. The vulnerabilities are collectively known as DNSpooq.&#13;
&#13;
Exploitation of these vulnerabilities could result in remote code execution or denial of service (DoS), or may allow an attacker to more easily forge DNS answers that can poison DNS caches, depending on the specific vulnerability.&#13;
&#13;
Multiple Cisco products are affected by these vulnerabilities.&#13;
&#13;
Cisco will release software updates that address these vulnerabilities. Any workarounds for a specific Cisco product or service will be documented in the relevant Cisco bugs, which are identified in the Vulnerable Products [&amp;#34;#vp&amp;#34;] section of this advisory.&#13;
&#13;
Note: At the time of publication, no Cisco products were found to be affected by the remote code execution and DoS vulnerabilities, which are identified by the following Common Vulnerabilities and Exposures (CVE) IDs:&#13;
&#13;
&#13;
CVE-2020-25681&#13;
CVE-2020-25682&#13;
CVE-2020-25683&#13;
CVE-2020-25687&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-dnsmasq-dns-2021-c5mrdf3g</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-CW75331 — Security fix for CVE-2020-25685 applied in: dnsmasq 2.83-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cw75331</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dnsmasq&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the dnsmasq package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dnsmasq&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the dnsmasq package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cw75331</guid>
    </item>
    <item>
      <title>cnvd-2021-16430</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-16430</link>
      <description>cnvd-2021-16430</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-16430</guid>
    </item>
    <item>
      <title>EUVD-2026-259474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259474</link>
      <description>EUVD-2026-259474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259474</guid>
    </item>
    <item>
      <title>fkie_cve-2020-25685</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-25685</link>
      <description>&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-25685</guid>
    </item>
    <item>
      <title>GHSA-9gxq-wfg7-72x4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9gxq-wfg7-72x4</link>
      <description>&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9gxq-wfg7-72x4</guid>
    </item>
    <item>
      <title>gsd-2020-25685</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-25685</link>
      <description>gsd-2020-25685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-25685</guid>
    </item>
    <item>
      <title>ICSA-21-019-01 — dnsmasq by Simon Kelley (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-019-01</link>
      <description>&lt;p&gt;Affected devices lack proper address/port check in the DNS reply_query function of dnsmasq.&lt;/p&gt;
&lt;p&gt;This could make it easier for remote off-path attackers to forge replies. Affected devices lack query resource name (RRNAME) checks in the DNS reply_query function of dnsmasq.&lt;/p&gt;
&lt;p&gt;This could allow a remote attacker to spoof DNS traffic that can lead to DNS cache poisoning. Affected devices lack sufficient entropy in dnsmasq to handle multiple DNS query requests from the same resource name (RRNAME).&lt;/p&gt;
&lt;p&gt;This could allow a remote attacker to spoof DNS traffic, using a birthday attack (RFC 5452), than can lead to DNS cache poisoning.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices lack proper address/port check in the DNS reply_query function of dnsmasq.&lt;/p&gt;
&lt;p&gt;This could make it easier for remote off-path attackers to forge replies. Affected devices lack query resource name (RRNAME) checks in the DNS reply_query function of dnsmasq.&lt;/p&gt;
&lt;p&gt;This could allow a remote attacker to spoof DNS traffic that can lead to DNS cache poisoning. Affected devices lack sufficient entropy in dnsmasq to handle multiple DNS query requests from the same resource name (RRNAME).&lt;/p&gt;
&lt;p&gt;This could allow a remote attacker to spoof DNS traffic, using a birthday attack (RFC 5452), than can lead to DNS cache poisoning.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-019-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-25685 — A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query dnsmasq checks in forward.…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-25685</link>
      <description>msrc_CVE-2020-25685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-25685</guid>
    </item>
    <item>
      <title>OESA-2021-1001 — dnsmasq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1001</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: dnsmasq, openEuler:20.03-LTS-SP1: dnsmasq&lt;/p&gt;
&lt;p&gt;Dnsmasq provides network infrastructure for small networks: DNS, DHCP, router advertisement and network boot. It is designed to be lightweight and have a small footprint, suitable for resource constrained routers and firewalls. It has also been widely used for tethering on smartphones and portable hotspots, and to support virtual networking in virtualisation frameworks. \r\n\r\n Security Fix(es):\r\n\r\n A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as valid, could use this flaw to cause a buffer overflow with arbitrary data in a heap memory segment, possibly executing code on the machine. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25681)\r\n\r\n
A flaw was found in dnsmasq. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an overflow with arbitrary data in a heap-allocated memory, possibly executing code on the machine. The flaw is in the rfc1035.c:extract_name() function, which writes data to the memory pointed by name assuming MAXDNAME*2 bytes are available in the buffer. However, in some code execution paths, it is possible extract_name() gets passed an offset from the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: dnsmasq, openEuler:20.03-LTS-SP1: dnsmasq&lt;/p&gt;
&lt;p&gt;Dnsmasq provides network infrastructure for small networks: DNS, DHCP, router advertisement and network boot. It is designed to be lightweight and have a small footprint, suitable for resource constrained routers and firewalls. It has also been widely used for tethering on smartphones and portable hotspots, and to support virtual networking in virtualisation frameworks. \r\n\r\n Security Fix(es):\r\n\r\n A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as valid, could use this flaw to cause a buffer overflow with arbitrary data in a heap memory segment, possibly executing code on the machine. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25681)\r\n\r\n
A flaw was found in dnsmasq. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an overflow with arbitrary data in a heap-allocated memory, possibly executing code on the machine. The flaw is in the rfc1035.c:extract_name() function, which writes data to the memory pointed by name assuming MAXDNAME*2 bytes are available in the buffer. However, in some code execution paths, it is possible extract_name() gets passed an offset from the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1001</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0124-1 — Security update for dnsmasq</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0124-1</link>
      <description>&lt;p&gt;Security update for dnsmasq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dnsmasq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0124-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0151 — Red Hat Security Advisory: dnsmasq security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0151</link>
      <description>&lt;p&gt;dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0151</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0162-1 — Security update for dnsmasq</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0162-1</link>
      <description>&lt;p&gt;Security update for dnsmasq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dnsmasq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0162-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-25685</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25685</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: dnsmasq, Ubuntu:16.04:LTS: dnsmasq, Ubuntu:18.04:LTS: dnsmasq, Ubuntu:20.04:LTS: dnsmasq&lt;/p&gt;
&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: dnsmasq, Ubuntu:16.04:LTS: dnsmasq, Ubuntu:18.04:LTS: dnsmasq, Ubuntu:20.04:LTS: dnsmasq&lt;/p&gt;
&lt;p&gt;A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25685</guid>
    </item>
    <item>
      <title>VDE-2021-012 — MB connect line: multiple products partially affected by DNSpooq</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-012</link>
      <description>&lt;p&gt;Multiple issues have been identified in dnsmasq &amp;lt; 2.83&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple issues have been identified in dnsmasq &amp;lt; 2.83&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-012</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2836 — dnsmasq: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2836</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in dnsmasq und mehreren Cisco Produkten ausnutzen, um beliebigen Programmcode auszuführen und um den DNS Cache zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in dnsmasq und mehreren Cisco Produkten ausnutzen, um beliebigen Programmcode auszuführen und um den DNS Cache zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2836</guid>
    </item>
  </channel>
</rss>
