VDB

CVE-2020-37127

CVE-2020-37127 PUBLISHED

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.

EPSS 0.00% · 0.3th percentile

Risk Scores

EPSS Score
0.00%
0.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSdnsmasq2.86-1.1ubuntu0.2, 2.86-1.1ubuntu0.3, 2.86-1.1
Ubuntu:Pro:14.04:LTSdnsmasq0, 2.66-4ubuntu1, 2.67-1
Ubuntu:Pro:16.04:LTSdnsmasq2.79-1ubuntu0.16.04.1+esm2, 2.75-1, 2.75-1ubuntu0.16.04.1
Ubuntu:Pro:18.04:LTSdnsmasq2.78-3, 2.79-1, *

Timeline

  • Feb 5, 2026 CVE Published
  • Feb 5, 2026 CVE Updated
  • Feb 6, 2026 EPSS Score
  • Feb 8, 2026 EPSS Score
  • Feb 10, 2026 EPSS Score
  • Feb 13, 2026 EPSS Score
  • Feb 15, 2026 EPSS Score
  • Feb 17, 2026 EPSS Score
  • Feb 19, 2026 EPSS Score
  • Feb 21, 2026 EPSS Score
  • Feb 24, 2026 EPSS Score
  • Feb 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›