PT-2026-39648 · Dnsmasq+3 · Dnsmasq+3

·

CVE-2026-2291

·

Published

2026-05-09

·

Updated

2026-07-22

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions dnsmasq versions 2.73 through 2.92
Description A heap buffer overflow exists in the DNS cache when processing DNS responses. The extract name() function can be abused because the software expands certain characters into longer escape sequences without ensuring the cache buffer is sized to hold the expanded result. Specifically, an unsafe strcpy() in the really insert() function within src/cache.c copies attacker-controlled name strings without bounds validation, overflowing a 1,025-byte bigname cache buffer. An attacker can exploit this by using a malicious upstream DNS server and crafted CNAME chains to corrupt memory, potentially leading to remote code execution, DNS cache poisoning to redirect lookups to attacker-controlled IP addresses, or a denial of service (DoS).
Recommendations Update dnsmasq to version 2.92rel2 or 2.93.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:19158
ALSA-2026:19373
ALSA-2026:20589
CVE-2026-2291
OESA-2026-2435
OESA-2026-2436
OESA-2026-2437
OESA-2026-2438
OESA-2026-2509
OPENSUSE-SU-2026:10821-1
OPENSUSE-SU-2026:20748-1
OPENSUSE-SU-2026:21192-1
RHSA-2026:19158
RHSA-2026:19373
RHSA-2026:20589
RHSA-2026:34508
SUSE-SU-2026:1826-1
SUSE-SU-2026:1827-1
SUSE-SU-2026:1828-1
SUSE-SU-2026:1934-1
SUSE-SU-2026:21626-1
SUSE-SU-2026:21633-1
SUSE-SU-2026:21640-1
SUSE-SU-2026:21677-1
SUSE-SU-2026:21733-1
SUSE-SU-2026:21788-1
SUSE-SU-2026:22454-1
SUSE-SU-2026:22496-1
SUSE-SU-2026:2458-1
USN-8268-1
ZDI-26-441

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Dnsmasq