Control: tags -1 + confirmed On Tue, 2026-09-01 at 18:02 +0200, Sven Geuer wrote: > This fixes CVE-2026-12725 and CVE-2026-12969 for trixie. These flaws > have been discovered and fixed upstream in pre-releases of > dnsmasq/2.93, currently in unstable in testing. > > [ Impact ] > CVE-2026-12725: A remote attacker able to supply a crafted DNS > response > may crash the dnsmasq process, resulting in denial of service. > > CVE-2026-12969: A remote attacker controlling a DNS zone can exploit > this via a crafted NXDOMAIN response to cause a 10-byte heap out-of- > bounds read, potentially accessing stale data from prior > transactions.
Please go ahead. Regards, Adam

