https://seclists.org/oss-sec/2026/q3/186: dnsmasq vulnerabilities, including attacker DNS dict, privilege escalation, and heap manipulation
Published Jul 20, 2026
·Updated
Affected Software
1 affected component
Dnsmasq Dnsmasq
Frequently Asked Questions
1
What is the severity of CVE-2026-2291?
CVE-2026-2291 has a high severity due to its potential for heap buffer overflow exploitation and DNS cache poisoning.
2
How do I fix CVE-2026-2291?
To fix CVE-2026-2291, update dnsmasq to the latest version where the vulnerability has been patched.
3
What systems are affected by CVE-2026-2291?
CVE-2026-2291 affects all versions of dnsmasq prior to the patched release on July 20, 2026.
4
What are the potential impacts of exploiting CVE-2026-2291?
Exploitation of CVE-2026-2291 could lead to DNS cache poisoning, redirecting users to malicious sites or causing denial of service.
5
Is there a proof of concept for CVE-2026-2291?
Yes, there are proofs of concept available that demonstrate how to exploit CVE-2026-2291 for malicious purposes.