{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/vex/2026/cve-2026-12725-els_os-centos-stream8els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-09T23:44:07Z",
      "generator": {
        "date": "2026-07-09T23:44:06Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-12725-ELS_OS-CENTOS-STREAM8ELS",
      "initial_release_date": "2026-06-22T16:16:00Z",
      "revision_history": [
        {
          "date": "2026-06-22T16:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-09T14:03:59Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-09T23:44:07Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-12725"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dnsmasq-utils-0:2.79-33.el8.x86_64",
                "product": {
                  "name": "dnsmasq-utils-0:2.79-33.el8.x86_64",
                  "product_id": "dnsmasq-utils-0:2.79-33.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/dnsmasq-utils@2.79-33.el8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dnsmasq-0:2.79-33.el8.x86_64",
                "product": {
                  "name": "dnsmasq-0:2.79-33.el8.x86_64",
                  "product_id": "dnsmasq-0:2.79-33.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/dnsmasq@2.79-33.el8?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
                  "product_id": "dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dnsmasq-utils@2.79-33.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
                  "product_id": "dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/dnsmasq@2.79-33.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dnsmasq-utils-0:2.79-33.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.x86_64"
        },
        "product_reference": "dnsmasq-utils-0:2.79-33.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dnsmasq-0:2.79-33.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.x86_64"
        },
        "product_reference": "dnsmasq-0:2.79-33.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-12725",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and\nquery logging are both enabled, logging of DS or DNSKEY replies containing\nunsupported algorithm or digest types can cause dnsmasq to write past the end\nof an internal logging buffer. A remote attacker able to supply such a DNS\nresponse may crash the dnsmasq process, resulting in denial of service.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.x86_64",
          "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-12725"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-12725",
          "url": "https://access.redhat.com/security/cve/CVE-2026-12725"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2490763",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490763"
        }
      ],
      "release_date": "2026-06-22T16:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-09T17:21:07.580332Z",
          "details": "This flaw is reachable only when both DNSSEC validation and verbose query logging are explicitly enabled in dnsmasq (non-default) and when logging DS/DNSKEY replies that use unsupported algorithms or digest types, which significantly narrows the trigger path and raises attack complexity. The effect is limited to a dnsmasq crash (availability only) with no confidentiality or integrity impact. In centrally managed VM/server environments where dnsmasq forwards to controlled upstream resolvers and query logging remains at its default (disabled), the practical likelihood of exploitation is low, so this CVE can be safely deprioritized.",
          "product_ids": [
            "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:dnsmasq-0:2.79-33.el8.x86_64",
            "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:dnsmasq-utils-0:2.79-33.el8.x86_64"
          ]
        }
      ]
    }
  ]
}