Vulnerability CVE-2022-0934: Information

Description

A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 29, 2022
Modified: March 7, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
dnsmasqsisyphus2.87-alt12.90-alt1ALT-PU-2022-2683-1307462Fixed
dnsmasqsisyphus_e2k2.87-alt2.12.90-alt1ALT-PU-2022-6319-1-Fixed
dnsmasqsisyphus_riscv642.87-alt22.90-alt1ALT-PU-2022-6312-1-Fixed
dnsmasqp102.87-alt2.12.90-alt1ALT-PU-2022-2830-1307467Fixed
dnsmasqp10_e2k2.87-alt2.12.90-alt1ALT-PU-2022-6516-1-Fixed
dnsmasqp92.85-alt2.p9.12.85-alt2.p9.1ALT-PU-2023-8012-2336361Fixed
dnsmasqc10f12.87-alt2.12.90-alt1ALT-PU-2022-2830-1307467Fixed
dnsmasqc9f22.87-alt2.12.90-alt1ALT-PU-2022-3323-1310904Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
      End excliding
      2.87

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*