{"id":"AZL-96617","summary":"CVE-2026-13002 affecting package dnsmasq 2.93-1","details":"A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.","modified":"2026-09-03T05:27:10Z","published":"2026-08-14T16:16:49Z","upstream":["CVE-2026-13002"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13002"}],"affected":[{"package":{"name":"dnsmasq","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/dnsmasq"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.93-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96617.json"}}],"schema_version":"1.9.0"}