Heap-based Out-of-Bounds Read in dnsmasq Affects DNS Resolution
CVE-2026-4891

5.3MEDIUM

Key Information:

Vendor

Dnsmasq

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-4891?

A heap-based out-of-bounds read vulnerability in the DNSSEC validation process of dnsmasq could allow remote attackers to execute denial of service attacks by sending specially crafted DNS packets. This vulnerability exploits flaws in the memory management of dnsmasq, a popular DNS forwarding service, potentially disrupting network operations for affected systems.

Affected Version(s)

dnsmasq 2.92rel2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.