Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2291

Опубликовано: 11 мая 2026
Источник: debian
EPSS Низкий

Описание

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsmasqfixed2.92-5package

Примечания

  • https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

  • https://xchglabs.com/blog/dnsmasq-five-cves.html

  • Introduced with: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=cbe379ad6b52a538a4416a7cd992817e5637ccf9 (v2.73rc5)

  • Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=014e909f787e808bb35daa546d3f8f3663918de2 (v2.93rc1)

  • https://blog.exodusintel.com/2026/07/20/dnsmasq-dns-remote-heap-buffer-overflow/

EPSS

Процентиль: 57%
0.0092
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

CVSS3: 6.5
redhat
3 месяца назад

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

CVSS3: 7.3
nvd
3 месяца назад

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

CVSS3: 7.3
msrc
2 месяца назад

CVE-2026-2291

suse-cvrf
3 месяца назад

Security update for dnsmasq

EPSS

Процентиль: 57%
0.0092
Низкий