CVE-2025-12199 | dnsmasq up to 2.73rc6 Config File src/network.c check_servers null pointer dereference (EUVD-2025-36060 / Nessus ID 276818)
A vulnerability classified as problematic was found in dnsmasq up to 2.73rc6. Affected by this vulnerability is the function check_servers of the file src/network.c of the component Config File Handler. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-12199. The attack needs to be approached locally. In addition, an exploit is available.
It is still unclear if this vulnerability genuinely exists.
Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities. The vendor was contacted early about this disclosure but did not respond in any way.