A vulnerability classified as problematic was found in dnsmasq up to 2.73rc6. Affected by this vulnerability is the function check_servers of the file src/network.c of the component Config File Handler. The manipulation results in null pointer dereference.

This vulnerability was named CVE-2025-12199. The attack needs to be approached locally. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.