Heap Buffer Overflow in dnsmasq Can Redirect DNS Lookups
CVE-2026-2291

Currently unrated

Key Information:

Vendor

Dnsmasq

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-2291?

The dnsmasq service contains a flaw in its extract_name() function, which can be exploited to cause a heap buffer overflow. This vulnerability allows attackers to inject incorrect DNS cache entries, leading to potential redirection of DNS queries to malicious IP addresses. Furthermore, this could enable denial-of-service conditions by disrupting normal DNS operations. Mitigating this vulnerability is crucial for maintaining network security and integrity.

Affected Version(s)

dnsmasq 2.92rel2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.