CVE-2026-2291
Published May 11, 2026
7.3
HIGHCVSS 3.1
EPSS 0.61%
Description
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
Affected products
-
- Version 0StatusaffectedConstraints<2.92rel2
- Version
No data.
No data.
Red Hat Enterprise Linux 10
dnsmasq-0:2.90-7.el10_2
Fixed · RHSA-2026:19158
Red Hat Enterprise Linux 8
dnsmasq-0:2.79-36.el8_10
Fixed · RHSA-2026:20589
Red Hat Enterprise Linux 9
dnsmasq-0:2.85-18.el9_8.1
Fixed · RHSA-2026:19373
Red Hat Enterprise Linux 9.6 Extended Update Support
dnsmasq-0:2.85-17.el9_6.1
Fixed · RHSA-2026:34508
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202608120446-0
Fixed · RHSA-2026:54553
Red Hat Enterprise Linux 6
dnsmasq
Out of support scope
Red Hat Enterprise Linux 7
dnsmasq
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dnsmasq-0:2.90-7.el10_2 | Fixed | RHSA-2026:19158 |
| Red Hat Enterprise Linux 8 | dnsmasq-0:2.79-36.el8_10 | Fixed | RHSA-2026:20589 |
| Red Hat Enterprise Linux 9 | dnsmasq-0:2.85-18.el9_8.1 | Fixed | RHSA-2026:19373 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dnsmasq-0:2.85-17.el9_6.1 | Fixed | RHSA-2026:34508 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202608120446-0 | Fixed | RHSA-2026:54553 |
| Red Hat Enterprise Linux 6 | dnsmasq | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | dnsmasq | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this issue as Moderate rather than Important. While DNS cache poisoning is possible, a process crash is the most likely outcome of a successful exploit. Also, standard upstream DNS resolvers reject the malformed responses before they reach dnsmasq, limiting exploitation to uncommon configurations where dnsmasq forwards directly to an attacker-controlled server.
References (13)
- http://www.openwall.com/lists/oss-security/2026/07/20/14
- https://access.redhat.com/security/cve/CVE-2026-2291 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439088 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29091 Advisory
- https://github.com/NixOS/nixpkgs/pull/519082
- https://github.com/NixOS/nixpkgs/pull/519093
- https://github.com/pi-hole/FTL/releases/tag/v6.6.2
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-2291
- https://thekelleys.org.uk/dnsmasq/CVE/
- https://www.cve.org/CVERecord?id=CVE-2026-2291
- https://www.kb.cert.org/vuls/id/471747
- https://www.suse.com/security/cve/CVE-2026-2291.html
Change history (0)
No recorded changes yet.