CVE-2026-2291 PUBLISHED

CVE-2026-2291

Assigner: certcc
Reserved: 10.02.2026 Published: 11.05.2026 Updated: 11.05.2026

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Product Status

Vendor dnsmasq
Product dnsmasq
Versions
  • Version 2.92rel2 is affected

References

Problem Types

  • CWE-190: Integer Overflow or Wraparound