ZDI-26-441: dnsmasq DNS Response Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Jul 15, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.
Affected Software
1 affected component
dnsmasq
Event History
Jul 15, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-441?
The severity of ZDI-26-441 is rated as 8.1 according to the CVSS system.
2
How do I fix ZDI-26-441?
To fix ZDI-26-441, update dnsmasq to the latest version that addresses this heap-based buffer overflow vulnerability.
3
What type of vulnerability is ZDI-26-441?
ZDI-26-441 is a heap-based buffer overflow vulnerability that allows for remote code execution.
4
Is authentication required to exploit ZDI-26-441?
No, authentication is not required to exploit the ZDI-26-441 vulnerability.
5
What are the potential impacts of ZDI-26-441?
Exploitation of ZDI-26-441 can lead to arbitrary code execution on affected dnsmasq installations.