Back

HIGH

CVE-2026-2291

Published May 11, 2026

Description

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Affected products

Remediation

Red Hat statement

Red Hat rates this issue as Moderate rather than Important. While DNS cache poisoning is possible, a process crash is the most likely outcome of a successful exploit. Also, standard upstream DNS resolvers reject the malformed responses before they reach dnsmasq, limiting exploitation to uncommon configurations where dnsmasq forwards directly to an attacker-controlled server.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published May 11, 2026
Updated Jul 20, 2026
Reserved Feb 10, 2026
CISA Vulnrichment
Updated May 13, 2026
NVD
Status Awaiting Analysis
Modified Jul 20, 2026
Red Hat
Severity Moderate
Public date May 9, 2026
ENISA EUVD
Assigner certcc
Published May 11, 2026
Updated Jul 20, 2026
Exploited since n/a
EUVD-2026-29091