VDB

ALPINE-CVE-2020-25686

ALPINE-CVE-2020-25686 PUBLISHED CVSS 3.700000047683716 LOW

A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to substantially reduce the number of attempts that it would have to perform to forge a reply and have it accepted by dnsmasq. This issue is mentioned in the "Birthday Attacks" section of RFC5452. If chained with CVE-2020-25684, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.10dnsmasq2.72-r1, 2.72-r0, 2.71-r0
Alpine:v3.11dnsmasq2.52-r1, 2.55-r0, 2.52-r1
Alpine:v3.16dnsmasq0, 0, 0
Alpine:v3.22dnsmasq0, 0, 0
Alpine:v3.12dnsmasq2.77-r0, 2.78-r0, 2.78-r1
Alpine:v3.21dnsmasq0, 0, 0
Alpine:v3.14dnsmasq2.62-r0, 0, 2.46-r0
Alpine:v3.19dnsmasq0, 0, 0
Alpine:v3.18dnsmasq0, 0, 0
Alpine:v3.20dnsmasq0, 0, 0
Alpine:v3.17dnsmasq0, 0, 0
Alpine:v3.23dnsmasq0, 0, 0
Alpine:v3.15dnsmasq0, 0, 0
Alpine:v3.13dnsmasq2.50-r1, 2.70-r0, 2.76-r4

Timeline

  • Jan 20, 2021 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›