Vulnerability record · CVE-2017-14496 · published 3 October 2017
CVE-2017-14496: dnsmasq add_pseudoheader integer underflow allows remote DoS
Canonical · Ubuntu Linux
dnsmasq before 2.78 contains an integer underflow in the add_pseudoheader function when the --add-mac, --add-cpe-id or --add-subnet option is enabled. A crafted DNS request triggers the underflow and crashes the resolver, disrupting DNS service for everything that depends on it.
Description
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated, low-complexity availability impact with a public exploit and very high EPSS, though no KEV listing and no code execution.
What it is
dnsmasq before 2.78 contains an integer underflow in the add_pseudoheader function when the --add-mac, --add-cpe-id or --add-subnet option is enabled. A crafted DNS request triggers the underflow and crashes the resolver, disrupting DNS service for everything that depends on it.
Impact
A remote, unauthenticated attacker can crash the dnsmasq process, causing denial of service for DNS resolution and any DHCP/DNS-dependent services on the host. No confidentiality or integrity impact is described; only availability is affected.
Attack surface
Reachable over the network by sending a crafted DNS request to a dnsmasq instance configured with --add-mac, --add-cpe-id or --add-subnet. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.66347 (99.2nd percentile) and a public Exploit-DB entry (42946) exists, indicating mature, widely available exploit code.
What to do
- Upgrade dnsmasq to 2.78 or later, or apply the vendor patch for your distribution (Red Hat RHSA-2017:2836, Debian DSA-3989, Ubuntu USN-3430-1/2).
- If patching is delayed, disable the --add-mac, --add-cpe-id and --add-subnet options where they are not strictly required.
- Restrict DNS service exposure to trusted networks and block untrusted UDP/TCP port 53 access at the perimeter.
- Monitor dnsmasq process restarts or crashes and treat repeated failures as a possible exploitation attempt.
Detection
- Alert on dnsmasq process crashes, core dumps or unexpected restarts in system logs.
- Inspect DNS query logs for malformed or unusual EDNS Client Subnet, MAC or CPE-ID option payloads reaching dnsmasq.
- Use the public Exploit-DB PoC (42946) to build IDS/IPS signatures for the crafted request pattern.
- Track availability gaps in DNS resolution from hosts that rely on the affected dnsmasq instance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-14496 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14496), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.