PT-2025-43758 · Dnsmasq · Dnsmasq
Zh_Vul
·
Published
2025-10-27
·
Updated
2025-11-02
·
CVE-2025-12200
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dnsmasq versions prior to 2.73rc6
Description
A flaw exists in dnsmasq related to the
parse dhcp opt function within the Config File Handler component, specifically in the file src/option.c. Manipulation of the argument m can lead to a null pointer dereference. This issue can only be exploited locally. The exploit for this issue has been publicly disclosed. The vendor was informed of this disclosure but did not respond.Recommendations
Update dnsmasq to a version newer than 2.73rc6.
Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dnsmasq