Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Summary: An off-by-two error in NSEC/NSEC3 type bitmap window iteration in dnssec.c causes an infinite loop when processing multi-window bitmaps. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. The bug has been present since DNSSEC support was added in v2.69 (2014), and I’ve confirmed exploitation on v2.81, v2.85, v2.91, v2.92, and current HEAD.