An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses…
OX·CWE-126·Published 2026-03-31
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.
Un atacante podría desencadenar una lectura fuera de límites al enviar un paquete de respuesta DNS manipulado, cuando código Lua personalizado utiliza newDNSPacketOverlay para analizar paquetes DNS. La lectura fuera de límites podría desencadenar un fallo, lo que llevaría a una denegación de servicio, o acceder a memoria no relacionada, lo que llevaría a una posible revelación de información.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 8.2 | 3.9 | 4.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| 3.1 | Primary | cve.org | 5.3 | — | — | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | Secondary | NVD | 5.3 | 3.9 | 1.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |