RHSA-2026:19158HighCVSS 8.8

Red Hat Security Advisory: dnsmasq security update

Published
May 19, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-2291 — dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion CVE-2026-4890 — dnsmasq: NSEC bitmap parsing infinite loop CVE-2026-4891 — dnsmasq: RRSIG rdlen underflow leading to heap OOB read CVE-2026-4892 — dnsmasq: DHCPv6 CLID buffer overflow in helper process CVE-2026-4893 — dnsmasq: Broken ECS source validation bypass CVE-2026-5172 — dnsmasq: extract_addresses() OOB read via malformed rdlen

🎯 Affected products22

  • Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-0:2.90-7.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-0:2.90-7.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-0:2.90-7.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-0:2.90-7.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-0:2.90-7.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debuginfo-0:2.90-7.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debuginfo-0:2.90-7.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debuginfo-0:2.90-7.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debuginfo-0:2.90-7.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debugsource-0:2.90-7.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debugsource-0:2.90-7.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debugsource-0:2.90-7.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-debugsource-0:2.90-7.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-0:2.90-7.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-0:2.90-7.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-0:2.90-7.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-0:2.90-7.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-debuginfo-0:2.90-7.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-debuginfo-0:2.90-7.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-debuginfo-0:2.90-7.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • dnsmasq-utils-debuginfo-0:2.90-7.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (9)