CVE-2026-4891
Published May 11, 2026
7.5
HIGHCVSS 3.1
EPSS 0.84%
Description
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Affected products
-
- Version 0StatusaffectedConstraints<2.92rel2
- Version
No data.
No data.
Red Hat Enterprise Linux 10
dnsmasq-0:2.90-7.el10_2
Fixed · RHSA-2026:19158
Red Hat Enterprise Linux 8
dnsmasq-0:2.79-36.el8_10
Fixed · RHSA-2026:20589
Red Hat Enterprise Linux 9
dnsmasq-0:2.85-18.el9_8.1
Fixed · RHSA-2026:19373
Red Hat Enterprise Linux 9.6 Extended Update Support
dnsmasq-0:2.85-17.el9_6.1
Fixed · RHSA-2026:34508
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202607151909-0
Fixed · RHSA-2026:40762
Red Hat Enterprise Linux 6
dnsmasq
Will not fix
Red Hat Enterprise Linux 7
dnsmasq
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dnsmasq-0:2.90-7.el10_2 | Fixed | RHSA-2026:19158 |
| Red Hat Enterprise Linux 8 | dnsmasq-0:2.79-36.el8_10 | Fixed | RHSA-2026:20589 |
| Red Hat Enterprise Linux 9 | dnsmasq-0:2.85-18.el9_8.1 | Fixed | RHSA-2026:19373 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dnsmasq-0:2.85-17.el9_6.1 | Fixed | RHSA-2026:34508 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202607151909-0 | Fixed | RHSA-2026:40762 |
| Red Hat Enterprise Linux 6 | dnsmasq | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | dnsmasq | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/errata/RHSA-2026:19158
- https://access.redhat.com/errata/RHSA-2026:19373
- https://access.redhat.com/errata/RHSA-2026:20589
- https://access.redhat.com/errata/RHSA-2026:34508
- https://access.redhat.com/errata/RHSA-2026:40762
- https://access.redhat.com/security/cve/CVE-2026-4891 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458517 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29153 Advisory
- https://github.com/NixOS/nixpkgs/pull/519082
- https://github.com/NixOS/nixpkgs/pull/519093
- https://github.com/pi-hole/FTL/releases/tag/v6.6.2
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-4891
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4891.json
- https://thekelleys.org.uk/dnsmasq/CVE/
- https://www.cve.org/CVERecord?id=CVE-2026-4891
- https://www.kb.cert.org/vuls/id/471747
Change history (0)
No recorded changes yet.