CVE-2026-13002
Received Received - Intake

DNSSEC Infinite Loop in dnsmasq Service

Vulnerability report for CVE-2026-13002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Red Hat, Inc.

Description

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat dnsmasq to 2026-09-30 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the dnssec.c library of dnsmasq, causing an infinite loop in the service. An attacker controlling a DNSSEC-signed zone can send a single crafted response to trigger this loop, hanging the dnsmasq process and stopping all DNS resolution for its clients.

Detection Guidance

Monitor dnsmasq process CPU usage spikes or unresponsiveness. Check logs for DNS resolution failures or timeouts. Use system monitoring tools like top, htop, or ps to detect high CPU usage by dnsmasq.

Impact Analysis

This vulnerability can disrupt DNS resolution for all clients relying on the affected dnsmasq instance, leading to network outages or degraded service. It may cause high CPU or memory usage, potentially crashing the system.

Compliance Impact

This vulnerability causes a denial-of-service (DoS) condition by hanging the dnsmasq service, disrupting DNS resolution for all clients. For compliance with GDPR or HIPAA, uninterrupted DNS resolution is critical for logging, authentication, and secure communications. A DoS could impair these functions, potentially violating availability requirements in both standards.

Mitigation Strategies

Disable DNSSEC validation temporarily if possible. Restrict access to dnsmasq to trusted networks only. Monitor for unusual DNS traffic patterns. Apply patches or updates as soon as they become available from your vendor.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart