A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Security readout for executives and security teams
Plain-English summary
A remotely supplied DNS packet can trigger a memory read error while dnsmasq validates DNSSEC, causing the DNS service to fail. The documented impact is service disruption, not data theft or modification. Organizations relying on dnsmasq for name resolution should promptly identify affected deployments and follow applicable vendor guidance.
Executive priority
Treat this as a high-priority availability risk, especially where dnsmasq supports critical DNS, network access, or embedded services. Prioritize exposure discovery now, then patch according to vendor guidance. Escalate systems with DNSSEC enabled and broad exposure, while recognizing that active exploitation is not established by the supplied evidence.
Technical view
CVE-2026-4891 is a heap-based out-of-bounds read (CWE-125) in dnsmasq DNSSEC validation. It is rated CVSS 3.1 7.5: network-accessible, low complexity, requiring neither privileges nor user interaction. The assessed security impact is high availability loss, with no stated confidentiality or integrity impact.
Likely exposure
Exposure is most likely where dnsmasq performs DNSSEC validation and processes attacker-influenced DNS traffic. The supplied affected entry lists only version "0," so it does not establish a reliable affected-version range. Check each operating-system or bundled-product advisory for applicability.
Exploitation context
The source bundle does not identify CVE-2026-4891 as a CISA KEV vulnerability and provides no evidence of active exploitation. Remote denial of service is technically plausible under the stated low-complexity network attack conditions, but observed exploitation prevalence is unknown.
Researcher notes
The core weakness, attack vector, and denial-of-service impact are clearly described. However, the supplied version value "0" is inadequate for precise vulnerability matching, and no definitive upstream fixed version is stated in the bundle. Product-specific applicability should therefore be established from dnsmasq, CERT/CC, Red Hat, NixOS, or Pi-hole advisories.
Mitigation direction
Identify dnsmasq installations and products that bundle it.
Consult dnsmasq and relevant distributor advisories for confirmed affected versions.
Apply applicable vendor-provided security updates after normal change validation.
Restrict unnecessary DNS traffic paths while awaiting vendor-specific remediation guidance.
Validation and detection
Record dnsmasq package versions and their supplying vendors.
Determine whether DNSSEC validation is enabled on each deployment.
Compare versions against the applicable vendor advisory or erratum.
Confirm updated package versions and DNS service health after remediation.
Monitor DNS service restarts or unexplained availability failures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.