Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:19158

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: dnsmasq security update

The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

Security Fix(es):

  • dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion (CVE-2026-2291)

  • dnsmasq: NSEC bitmap parsing infinite loop (CVE-2026-4890)

  • dnsmasq: RRSIG rdlen underflow leading to heap OOB read (CVE-2026-4891)

  • dnsmasq: DHCPv6 CLID buffer overflow in helper process (CVE-2026-4892)

  • dnsmasq: Broken ECS source validation bypass (CVE-2026-4893)

  • dnsmasq: extract_addresses() OOB read via malformed rdlen (CVE-2026-5172)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
dnsmasq-utilsaarch647.el10_2dnsmasq-utils-2.90-7.el10_2.aarch64.rpm
dnsmasqaarch647.el10_2dnsmasq-2.90-7.el10_2.aarch64.rpm
dnsmasqx86_647.el10_2dnsmasq-2.90-7.el10_2.x86_64.rpm
dnsmasq-utilsx86_647.el10_2dnsmasq-utils-2.90-7.el10_2.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
17 дней назад

ELSA-2026-19158: dnsmasq security update (IMPORTANT)

suse-cvrf
3 месяца назад

Security update for dnsmasq

suse-cvrf
около 1 месяца назад

Security update for dnsmasq

suse-cvrf
3 месяца назад

Security update for dnsmasq

rocky
2 месяца назад

Important: dnsmasq security update