CVE-2026-2291: Dnsmasq
High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
Affected products
- Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)
Published 2026-05-11. Last modified 2026-07-20.