{"id":"AZL-91164","summary":"CVE-2026-12969 affecting package dnsmasq for versions less than 2.93-1","details":"An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.","modified":"2026-08-28T17:48:12.248834501Z","published":"2026-06-23T14:17:22Z","upstream":["CVE-2026-12969"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12969"}],"affected":[{"package":{"name":"dnsmasq","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/dnsmasq"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.93-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91164.json"}}],"schema_version":"1.9.0"}