Vulnerability record · CVE-2017-14494 · published 3 October 2017
CVE-2017-14494: dnsmasq DHCPv6 relay memory information disclosure
Canonical · Ubuntu Linux
dnsmasq before 2.78, when configured as a DHCPv6 relay, mishandles forwarded requests in a way that exposes sensitive memory contents. A remote attacker can read process memory, which may contain configuration data, credentials, or other secrets. The flaw is an information exposure (CWE-200) with a CVSS 3.0 base score of 5.9 (Medium).
Description
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityAlthough CVSS rates it Medium (5.9), the high EPSS score and public exploit availability raise the practical risk for exposed DHCPv6 relay deployments.
What it is
dnsmasq before 2.78, when configured as a DHCPv6 relay, mishandles forwarded requests in a way that exposes sensitive memory contents. A remote attacker can read process memory, which may contain configuration data, credentials, or other secrets. The flaw is an information exposure (CWE-200) with a CVSS 3.0 base score of 5.9 (Medium).
Impact
An attacker gains read access to sensitive memory contents from the dnsmasq process, potentially leaking configuration details or other data held in memory. There is no integrity or availability impact; the loss is confidentiality only.
Attack surface
Reachable over the network (AV:N) by sending crafted DHCPv6 forwarded requests to a dnsmasq instance acting as a relay. No authentication (PR:N) and no user interaction (UI:N) are required, though the attack complexity is rated High (AC:H).
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.67549 (99.275th percentile), indicating a meaningful probability of exploitation activity. A public Exploit-DB entry (42944) exists, and multiple vendor advisories and patches are referenced.
What to do
- Upgrade dnsmasq to 2.78 or later; apply the vendor patches referenced in RHSA-2017:2836, RHSA-2017:2837, USN-3430-1/2, and DSA-3989.
- If dnsmasq is not required as a DHCPv6 relay, disable relay functionality to remove the attack path.
- Restrict network access to DHCPv6 relay ports so only trusted relay agents and clients can reach the service.
- Monitor vendor advisories for downstream products (Ubuntu, Debian, Red Hat, SUSE, Synology, Aruba, NVIDIA) and patch embedded dnsmasq copies.
- Where immediate patching is not possible, isolate relay instances on segmented networks to limit exposure.
Detection
- Monitor dnsmasq logs for abnormal DHCPv6 relay request patterns or malformed forwarded requests.
- Use network monitoring to detect unexpected DHCPv6 relay traffic from untrusted sources to dnsmasq hosts.
- Check host and package inventories for dnsmasq versions below 2.78 and flag unpatched relay configurations.
- Review memory or crash dumps from dnsmasq processes for signs of unexpected memory disclosure if suspicious activity is suspected.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-14494 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14494), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.