CVE-2026-2291: Dnsmasq

High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Affected products

  • Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)

Published 2026-05-11. Last modified 2026-07-20.