PT-2025-43757 · Dnsmasq · Dnsmasq

Zh_Vul

·

Published

2025-10-27

·

Updated

2025-11-02

·

CVE-2025-12199

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dnsmasq versions up to 2.73rc6
Description A flaw exists in dnsmasq that involves a null pointer dereference within the check servers function, located in the src/network.c file of the Config File Handler component. This issue can be triggered through local exploitation. The exploit for this issue has been publicly released, and attempts to notify the vendor were unsuccessful.
Recommendations Versions prior to 2.73rc6 should be used.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2025-12199

Affected Products

Dnsmasq