Описание
Security update for dnsmasq
This update for dnsmasq fixes the following issues
Security issues:
- CVE-2026-2291: dnsmasq can be abused to record false cached data enabling DoS or attacker redirect (bsc#1258251).
- CVE-2026-4890: DoS vulnerability in the DNSSEC validation (bsc#1265001).
- CVE-2026-4891: heap-based out-of-bounds read vulnerability in the DNSSEC validation (bsc#1265002).
- CVE-2026-4892: heap-based out-of-bounds write vulnerability in the DHCPv6 implementation (bsc#1265003).
- CVE-2026-4893: information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks (bsc#1265004).
- CVE-2026-5172: buffer overflow in dnsmasq's extract_addresses() function (bsc#1265006).
- CVE-2026-6507: out-of-bounds write in DHCP BOOTREPLY processing can lead to denial of service (bsc#1262487).
Non security issues:
- aardvark-dns upstream tests make dnsmasq dump core (bsc#1247812).
- Drop rcFOO symlinks for CODE16 (jsc#PED-266.
- libnettle: update to 4.0 breaks dnsmasq and gnutls (bsc#1257934).
- unknown user or group: dnsmasq with latest proposed dnsmasq update when doing virsh net-start (bsc#1235517).
- Update to security release 2.92rel2.
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1235517
- SUSE Bug 1235834
- SUSE Bug 1247812
- SUSE Bug 1257934
- SUSE Bug 1258251
- SUSE Bug 1262487
- SUSE Bug 1265001
- SUSE Bug 1265002
- SUSE Bug 1265003
- SUSE Bug 1265004
- SUSE Bug 1265006
- SUSE CVE CVE-2026-2291 page
- SUSE CVE CVE-2026-4890 page
- SUSE CVE CVE-2026-4891 page
- SUSE CVE CVE-2026-4892 page
- SUSE CVE CVE-2026-4893 page
- SUSE CVE CVE-2026-5172 page
- SUSE CVE CVE-2026-6507 page
Описание
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
Затронутые продукты
Ссылки
- CVE-2026-2291
- SUSE Bug 1258251
Описание
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Затронутые продукты
Ссылки
- CVE-2026-4890
- SUSE Bug 1265001
Описание
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Затронутые продукты
Ссылки
- CVE-2026-4891
- SUSE Bug 1265002
Описание
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Затронутые продукты
Ссылки
- CVE-2026-4892
- SUSE Bug 1265003
Описание
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
Затронутые продукты
Ссылки
- CVE-2026-4893
- SUSE Bug 1265004
Описание
A buffer overflow in dnsmasq's extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record's end.
Затронутые продукты
Ссылки
- CVE-2026-5172
- SUSE Bug 1265006
Описание
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and resulting in a denial of service (DoS).
Затронутые продукты
Ссылки
- CVE-2026-6507
- SUSE Bug 1262487