Multiple Vulnerabilities in Dnsmasq (CVE-2026-4890, CVE-2026-4891, CVE-2026-42959, CVE-2026-4892, CVE-2026-4893)
39093
02 October 2026
02 October 2026
CLOSED
LOW
CVE-2026-4890, CVE-2026-4891, CVE-2026-42959, CVE-2026-4892, CVE-2026-4893
|
Brocade Security Advisory ID |
BSA-2026-4105 |
|
Component |
Dnsmasq |
|
|
|
Summary
Brocade is issuing a security advisory addressing multiple vulnerabilities identified in dnsmasq component used across affected products. These vulnerabilities range from memory corruption and heap-based out-of-bounds reads/writes to uncontrolled resource consumption leading to Denial of Service (DoS) and potential information exposure.
Vulnerability Details
CVE-2026-42959CVE-2026-4890: Crash during DNSSEC Validation of Malicious Content
- Severity / CVSS v3 Base Score: High / 8.7
- Common Weakness Enumeration: CWE-400 (Uncontrolled Resource Consumption)
- Description: A flaw in the DNSSEC validation routine allows remote attackers to trigger a process crash by serving or forwarding malicious DNS content, leading to a system-wide service disruption.
CVE-2026-4890: Denial of Service in DNSSEC Validation via Crafted Packet
- Severity / CVSS v3 Base Score: High / 7.5
- Common Weakness Enumeration: CWE-400 (Uncontrolled Resource Consumption)
- Description: An unauthenticated attacker can send a specially crafted DNS packet to trigger excessive resource consumption during DNSSEC validation, causing a Denial of Service (DoS) condition on the dnsmasq service.
CVE-2026-4892: Memory Corruption via Heap-Based Out-of-Bounds Write
- Severity / CVSS v3 Base Score: Medium / 6.4
- Common Weakness Enumeration: CWE-787 (Out-of-bounds Write)
- Description: A heap-based out-of-bounds write flaw exists in the helper.c component of dnsmasq. An attacker capable of sending tailored requests can cause memory corruption, potentially leading to service instability or arbitrary code execution.
CVE-2026-4891: Heap-Based Out-of-Bounds Read in DNSSEC Validation
- Severity / CVSS v3 Base Score: Medium / 5.3
- Common Weakness Enumeration: CWE-125 (Out-of-bounds Read)
- Description: Processing a specially crafted DNS packet during DNSSEC validation can cause dnsmasq to perform a heap-based out-of-bounds read, potentially leading to a process crash or limited disclosure of memory contents.
CVE-2026-4893: Data Exposure via Source Check Bypass in forward.c
- Severity / CVSS v3 Base Score: Medium / 4.6
- Common Weakness Enumeration: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)
- Description: A logic flaw in forward.c allows attackers to bypass source address checks, potentially leading to unauthorized data exposure or information leakage.
Products Confirmed Not Affected
- Brocade ASCG Standard - [VEX]:ASCG:Vulnerable_code_not_in_execute_path
Solution
- A security update is provided in Brocade ASCG 3.5.0
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/30/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.