vulnerability
FreeBSD: VID-3f321a5a-b33b-11ec-80c2-1bb2c6a00592 (CVE-2022-0934): dnsmasq -- heap use-after-free in dhcp6_no_relay
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Apr 3, 2022 | Nov 4, 2022 | Dec 10, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Apr 3, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
Petr Menšík reports: Possible vulnerability [...] found in latest dnsmasq. It [was] found with help of oss-fuzz Google project by me and short after that independently also by Richard Johnson of Trellix Threat Labs. It is affected only by DHCPv6 requests, which could be crafted to modify already freed memory. [...] We think it might be triggered remotely, but we do not think it could be used to execute remote code.
Solutions
freebsd-upgrade-package-dnsmasqfreebsd-upgrade-package-dnsmasq-devel
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.