View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2021-3448 severity moderate: SUSE including 22 source package names (0.45.0.8.17.1:dnsmasq-2.86-7.14.1, dnsmasq, …), 63 product×package rows across 53 product lines (Container suse/sles/15.3/virt-launcher, HPE Helion OpenStack 8, … (53 product lines)): Fixed 61, Known Not Affected 2.
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier. The highest threat from this vulnerability is to data integrity.