What is CVE-2026-13002?
CVE-2026-13002 is an infinite loop vulnerability in the dnssec.c library within the dnsmasq service. An attacker controlling a DNSSEC-signed zone can hang the dnsmasq process with a crafted response, halting all DNS resolution for clients. Updating dnsmasq to the latest patched version is strongly advised.
Azərbaycanca: CVE-2026-13002 dnsmasq xidmətindəki dnssec.c kitabxanasında sonsuz dövr zəifliyidir. DNSSEC imzalı hər hansısa zonaya nəzarət edən hücumçu, xüsusi hazırlanmış cavabla dnsmasq prosesini asaraq bütün DNS həllini dayandıra bilər. dnsmasq-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What can an attacker exploiting CVE-2026-13002 achieve?
An attacker can hang the dnsmasq process with a crafted DNSSEC response, halting all DNS resolution for clients.
What mitigation is recommended for CVE-2026-13002?
Updating dnsmasq to the latest patched version is advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.