Vulnerability record · CVE-2020-25687 · published 20 January 2021
CVE-2020-25687: dnsmasq DNSSEC heap buffer overflow via extract_name length checks
Thekelleys · Dnsmasq
dnsmasq before 2.83 has a heap-based buffer overflow in rfc1035.c:extract_name() when DNSSEC is enabled and before received DNS entries are validated. Missing length checks let a crafted name drive memcpy() with a negative size in sort_rrset(), crashing dnsmasq. The main threat is loss of availability of the DNS resolver or forwarder.
Description
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name(), which could be abused to make the code execute memcpy() with a negative size in sort_rrset() and cause a crash in dnsmasq, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityCVSS rates it medium (5.9) with availability-only impact and high attack complexity, but the very high EPSS and wide dnsmasq deployment warrant prompt patching.
What it is
dnsmasq before 2.83 has a heap-based buffer overflow in rfc1035.c:extract_name() when DNSSEC is enabled and before received DNS entries are validated. Missing length checks let a crafted name drive memcpy() with a negative size in sort_rrset(), crashing dnsmasq. The main threat is loss of availability of the DNS resolver or forwarder.
Impact
A remote attacker able to supply valid DNS replies can overflow heap memory and crash dnsmasq, causing denial of service. The record describes only availability impact; no confidentiality or integrity gain is stated.
Attack surface
Reached over the network by sending DNS replies to a dnsmasq instance that has DNSSEC enabled. No authentication or user interaction is required per the CVSS vector (AV:N/AC:H/PR:N/UI:N), though the attack is rated high complexity.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is very high (0.86692, 99.7th percentile), and references include a patch and the DNSPooq disclosure, but no public exploit is confirmed in this record.
What to do
- Upgrade dnsmasq to 2.83 or later, or apply the vendor patch referenced in the Red Hat bug and distribution advisories.
- Apply the Debian, Fedora and Gentoo package updates for the affected releases.
- If DNSSEC is not required, consider disabling it as a temporary risk reduction, understanding this changes resolver behavior.
- Restrict which upstream resolvers and networks can send DNS replies to the dnsmasq instance where feasible.
- Monitor dnsmasq processes for repeated crashes and restart loops after applying compensating controls.
Detection
- Alert on dnsmasq process crashes, core dumps or unexpected restarts, especially on DNSSEC-enabled resolvers.
- Watch for repeated malformed or oversized DNS responses from upstream servers to dnsmasq.
- Track dnsmasq version inventory to find hosts still below 2.83.
- Correlate resolver availability drops with unusual upstream DNS traffic patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-25687 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-25687), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.