{"id":170683,"date":"2026-05-15T00:24:28","date_gmt":"2026-05-14T22:24:28","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root"},"modified":"2026-05-15T00:24:28","modified_gmt":"2026-05-14T22:24:28","slug":"uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root","title":{"rendered":"Vulnerabilities in dnsmasq allowing DNS cache poisoning and execution of code with root privileges","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the Dnsmasq package, which combines a caching DNS resolver, DHCP server, IPv6 route announcement service, and network boot system, 6 vulnerabilities have been identified that allow code execution with root privileges, domain redirection to another IP, memory content disclosure of processes, and service crashes. The issues have been resolved in the dnsmasq 2.92rel2 release. Fixes are also available in the form of patches.             <\/p>\n<p>Identified issues:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2026-4892 \u2014 buffer overflow in the DHCPv6 implementation, allowing an attacker with access to the local network to execute code with root privileges by sending a specially crafted DHCPv6 packet. The overflow occurs because the DHCPv6 CLID is written to the buffer without considering that the data in the packet is stored in hexadecimal representation, which uses three bytes for each actual byte of CLID (for example, saving a 1000-byte CLID will result in writing 3000 bytes).\n<li class=\"l\"> CVE-2026-2291 \u2014 buffer overflow in the extract_name() function, allowing an attacker to inject fake records into the DNS cache and achieve redirection. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/domain\/\" title=\"domain\" data-wpil-keyword-link=\"linked\">domain<\/a> to another IP address. The overflow occurred due to buffer allocation without considering the escaping of certain characters in the internal representation of the domain name in dnsmasq.\n<li class=\"l\"> CVE-2026-4893 \u2014 information leak allowing bypass of verification by sending a specially crafted DNS packet with client subnet information (RFC 7871). The vulnerability can be exploited to modify the DNS response routing and redirect users to the attacker's domain. The vulnerability arises because the length of the OPT record was passed to the check_source() function instead of the packet length, causing the function to always return a successful verification result.\n<li class=\"l\"> CVE-2026-4891 \u2014 reading from outside the buffer boundary during DNSSEC validation, leading to leakage of data from the process's memory in the response when processing a specially crafted DNS query.\n<li class=\"l\"> CVE-2026-4890 \u2014 infinite loop during DNSSEC validation, allowing denial of service via sending a specially crafted DNS packet.\n<li class=\"l\"> CVE-2026-5172 \u2014 reading from outside the buffer in the extract_addresses() function, leading to a crash when processing specially crafted DNS responses.  <\/ul>\n<p>The status of vulnerability remediation in distributions can be assessed on the following pages (if a page is unavailable, it means the distribution developers have not yet begun to address the issue): Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch, Fedora, OpenWRT, FreeBSD. The Dnsmasq project is used in the Android platform and specialized distributions like OpenWrt and DD-WRT, as well as in the firmware of wireless routers from many manufacturers. In regular distributions, Dnsmasq can be installed when using libvirt to provide DNS service functionality. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/vps\/abuzoustojchivye-vps\/\" title=\"virtual machines\" data-wpil-keyword-link=\"linked\">virtual machines<\/a> or activated in the NetworkManager configurator.<br \/>\n<br \/>Source: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65431\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Dnsmasq, \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044e\u0449\u0435\u043c \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0439 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440, \u0441\u0435\u0440\u0432\u0435\u0440 DHCP, \u0441\u0435\u0440\u0432\u0438\u0441 \u0434\u043b\u044f \u0430\u043d\u043e\u043d\u0441\u043e\u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432 IPv6 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u043e \u0441\u0435\u0442\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 6 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0434\u043e\u043c\u0435\u043d \u043d\u0430 \u0434\u0440\u0443\u0433\u043e\u0439 IP, \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0438 \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 dnsmasq 2.92rel2. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u0436\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0432 \u0444\u043e\u0440\u043c\u0435 \u043f\u0430\u0442\u0447\u0435\u0439. \u0412\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b: [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-170683","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Dnsmasq, \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044e\u0449\u0435\u043c \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0439 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440, \u0441\u0435\u0440\u0432\u0435\u0440 DHCP, \u0441\u0435\u0440\u0432\u0438\u0441 \u0434\u043b\u044f \u0430\u043d\u043e\u043d\u0441\u043e\u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432 IPv6 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u043e \u0441\u0435\u0442\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 6 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0434\u043e\u043c\u0435\u043d.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 dnsmasq, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0438\u0435 \u043e\u0442\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 DNS-\u043a\u044d\u0448\u0430 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Dnsmasq, \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044e\u0449\u0435\u043c \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0439 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440, \u0441\u0435\u0440\u0432\u0435\u0440 DHCP, \u0441\u0435\u0440\u0432\u0438\u0441 \u0434\u043b\u044f \u0430\u043d\u043e\u043d\u0441\u043e\u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432 IPv6 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u043e \u0441\u0435\u0442\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 6 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0434\u043e\u043c\u0435\u043d.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-14T22:24:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-14T22:24:28+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in dnsmasq allow for DNS cache poisoning and code execution with root privileges | ProHoster","description":"The Dnsmasq package, which combines a caching DNS resolver, a DHCP server, a service for announcing IPv6 routes, and a network booting system, has revealed 6 vulnerabilities that allow for code execution with root privileges and domain redirection.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 dnsmasq, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0438\u0435 \u043e\u0442\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 DNS-\u043a\u044d\u0448\u0430 \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster","og:description":"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 Dnsmasq, \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044e\u0449\u0435\u043c \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0449\u0438\u0439 DNS-\u0440\u0435\u0437\u043e\u043b\u0432\u0435\u0440, \u0441\u0435\u0440\u0432\u0435\u0440 DHCP, \u0441\u0435\u0440\u0432\u0438\u0441 \u0434\u043b\u044f \u0430\u043d\u043e\u043d\u0441\u043e\u0432 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u043e\u0432 IPv6 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u043f\u043e \u0441\u0435\u0442\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 6 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u0438\u0442\u044c \u0434\u043e\u043c\u0435\u043d.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-dnsmasq-dopuskayushhie-otravlenie-dns-kesha-i-vypolnenie-koda-s-pravami-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-14T22:24:28+00:00","article:modified_time":"2026-05-14T22:24:28+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/170683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=170683"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/170683\/revisions"}],"predecessor-version":[{"id":170707,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/170683\/revisions\/170707"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=170683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=170683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=170683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}