A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name(), which could be abused to make the code execute memcpy() with a negative size in sort_rrset() and cause a crash in dnsmasq, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVE-2020-25687
Score elevated to 9.0 because EPSS predicts 87% probability of exploitation within the next 30 days (top 0.3% of all CVEs). NVD baseline CVSS 5.9 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 87%
A fix is available — apply it.
- CVSS v3
- 5.9
- EG Score
- 9.0(high)
- EG Risk
- —
- EPSS
- 99.7%
- KEV
- Not listed
Published
January 20, 2021
Last Modified
November 4, 2025
References (15)
- secalert@redhathttps://bugzilla.redhat.com/show_bug.cgi?id=1891568
- secalert@redhathttps://lists.debian.org/debian-lts-announce/2021/03/msg00027.html
- secalert@redhathttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGB7HL3OWHTLEPSMLDGOMXQKG3KM2QME/
- secalert@redhathttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WYW3IR6APUSKOYKL5FT3ACTIHWHGQY32/
- secalert@redhathttps://security.gentoo.org/glsa/202101-17
- secalert@redhathttps://www.debian.org/security/2021/dsa-4844
- secalert@redhathttps://www.jsof-tech.com/disclosures/dnspooq/
- af854a3a-2127-422b-91ae-364da2661108https://bugzilla.redhat.com/show_bug.cgi?id=1891568
- af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2021/03/msg00027.html
- af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGB7HL3OWHTLEPSMLDGOMXQKG3KM2QME/
- af854a3a-2127-422b-91ae-364da2661108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WYW3IR6APUSKOYKL5FT3ACTIHWHGQY32/
- af854a3a-2127-422b-91ae-364da2661108https://security.gentoo.org/glsa/202101-17
- af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2021/dsa-4844
- af854a3a-2127-422b-91ae-364da2661108https://www.jsof-tech.com/disclosures/dnspooq/
- af854a3a-2127-422b-91ae-364da2661108https://www.kb.cert.org/vuls/id/434904
Patch Availability(4)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | dnsmasq-utils (2.82-1ubuntu1.1) @ groovy | 2026-05-26 | ubuntu |
| redhat | dnsmasq-0:2.79-13.el8_3.1 | 2021-01-19 | redhat |
| redhat | dnsmasq-0:2.79-6.el8_1.1 | 2021-01-19 | redhat |
| redhat | dnsmasq-0:2.79-11.el8_2.2 | 2021-01-19 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(5)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
- Microsoft MSRCCVE-2020-256872021-01-27
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker who can create valid DNS replies to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name() which could be abused to make the code execute memcpy() with a negative size in sort_rrset() and cause a crash in dnsmasq resulting in a denial of service. The highest threat from this vulnerability is to system availability.
- Red HatRHSA-2021:0150MODERATE2021-01-19
RHSA-2021:0150 — Moderate
- Red HatRHSA-2021:0151MODERATE2021-01-19
RHSA-2021:0151 — Moderate
- Red HatRHSA-2021:0152MODERATE2021-01-19
RHSA-2021:0152 — Moderate
- UbuntuUSN-4698-1MEDIUM
Dnsmasq vulnerabilities
Data Freshness Timeline
(refreshed 8× in last 7d / 24× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 21:28 UTCEG score recompute▲ 3.10
- 2026-07-22 21:28 UTCVendor advisory
- 2026-07-22 21:28 UTCGHSA enrichment
- 2026-07-22 14:05 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-19 03:22 UTCOSV refresh
- 2026-07-16 16:59 UTCEPSS rescore
- 2026-07-15 01:57 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-04 06:29 UTCEPSS rescore
- 2026-07-04 06:28 UTCEPSS rescore
- 2026-07-01 10:18 UTCOSV refresh
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-28 14:05 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-16 17:50 UTCEPSS rescore
Show 33 moreShow fewer
- 2026-06-16 17:50 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 23:15 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 15:43 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 13:20 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-06 13:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-04 13:10 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-29 13:42 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-26 21:50 UTCEG score recompute
- 2026-05-26 21:50 UTCVendor advisory
- 2026-05-26 21:50 UTCGHSA enrichment
- 2026-05-24 16:48 UTCEPSS rescore
Frequently asked(5)
What is CVE-2020-25687?
When was CVE-2020-25687 disclosed?
Is CVE-2020-25687 actively exploited?
What is the CVSS score of CVE-2020-25687?
How do I remediate CVE-2020-25687?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2020-25687
Is Your Infrastructure Affected by CVE-2020-25687?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.