Vulnerabilities in dnsmasq allowing DNS cache poisoning and execution of code with root privileges

In the Dnsmasq package, which combines a caching DNS resolver, DHCP server, IPv6 route announcement service, and network boot system, 6 vulnerabilities have been identified that allow code execution with root privileges, domain redirection to another IP, memory content disclosure of processes, and service crashes. The issues have been resolved in the dnsmasq 2.92rel2 release. Fixes are also available in the form of patches.

Identified issues:

  • CVE-2026-4892 — a buffer overflow in the DHCPv6 implementation, allowing an attacker with access to the local network to execute code with root privileges by sending a specially crafted DHCPv6 packet. The overflow occurs because the writing of DHCPv6 CLID to the buffer does not account for the hexadecimal representation of the data, which uses three bytes '%xx' for each actual byte of CLID (for example, saving a 1000-byte CLID results in writing 3000 bytes).
  • CVE-2026-2291 — a buffer overflow in the extract_name() function, allowing an attacker to inject dummy records into the DNS cache and achieve redirection domain to another IP address. The overflow occurred due to buffer allocation without considering the escaping of certain characters in the internal representation of the domain name in dnsmasq.
  • CVE-2026-4893 — an information leak that allows bypassing checks by sending a specially crafted DNS packet with client subnet information (RFC 7871). The vulnerability can be exploited to alter the DNS response route and redirect users to the attacker's domain. The vulnerability is caused by passing the length of the OPT record to the check_source() function instead of the length of the packet, which always resulted in a successful verification outcome.
  • CVE-2026-4891 — reading out of buffer bounds during DNSSEC validation, leading to the leakage of data from the process memory in response to a specially crafted DNS query.
  • CVE-2026-4890 — an infinite loop during DNSSEC validation, allowing denial of service through sending a specially crafted DNS packet.
  • CVE-2026-5172 — reading out of bounds in the extract_addresses() function, leading to a crash when processing specially crafted DNS responses.

The status of vulnerability remediation in distributions can be assessed on the following pages (if a page is unavailable, it means the distribution developers have not yet begun to address the issue): Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch, Fedora, OpenWRT, FreeBSD. The Dnsmasq project is used in the Android platform and specialized distributions like OpenWrt and DD-WRT, as well as in the firmware of wireless routers from many manufacturers. In regular distributions, Dnsmasq can be installed when using libvirt to provide DNS service functionality. virtual machines or activated in the NetworkManager configurator.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster