VYPR
Critical severity9.8NVD Advisory· Published Jan 1, 2022· Updated Jun 17, 2026

CVE-2021-45955

CVE-2021-45955

Description

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:thekelleys:dnsmasq:2.86:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:thekelleys:dnsmasq:2.86:*:*:*:*:*:*:*
    • (no CPE)range: 2.86
  • Dnsmasq/Dnsmasqdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.