oss-sec mailing list archives

Re: Questionable CVE's reported against dnsmasq


From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Wed, 29 Oct 2025 17:12:03 -0700

On 10/27/25 09:34, Alan Coopersmith wrote:
Among the new CVE's published this weekend were these from the VulDB CNA:

CVE-2025-12198

    A vulnerability has been found in dnsmasq up to 2.73rc6. Affected is the
[...]

CVE-2025-12199

    A vulnerability was found in dnsmasq up to 2.73rc6. Affected by this
[...]

CVE-2025-12200

    A vulnerability was determined in dnsmasq up to 2.73rc6. Affected by this
[...]

The folks on the dnsmasq mailing list also pointed out the version claimed is
a release candidate from 10 years ago, not anything current:

https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2025q4/018338.html

(The current stable release of dnsmasq is version 2.91 from March of this year.)

--
        -Alan Coopersmith-                 alan.coopersmith () oracle com
         Oracle Solaris Engineering - https://blogs.oracle.com/solaris


Current thread: