CVE-2026-4890: Dnsmasq

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Affected products

  • Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)
  • Red Hat Red Hat Enterprise Linux 10: before 0:2.90-7.el10_2 (fixed in 0:2.90-7.el10_2)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 0:2.79-36.el8_10 (fixed in 0:2.79-36.el8_10)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.85-18.el9_8.1 (fixed in 0:2.85-18.el9_8.1)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:2.85-17.el9_6.1 (fixed in 0:2.85-17.el9_6.1)
  • Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202607151909-0 (fixed in 4.19.9.6.202607151909-0)

Published 2026-05-11. Last modified 2026-08-25.