Details:
The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.
Security Fix(es):
dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion (CVE-2026-2291)
dnsmasq: NSEC bitmap parsing infinite loop (CVE-2026-4890)
dnsmasq: RRSIG rdlen underflow leading to heap OOB read (CVE-2026-4891)
dnsmasq: DHCPv6 CLID buffer overflow in helper process (CVE-2026-4892)
dnsmasq: Broken ECS source validation bypass (CVE-2026-4893)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:2.85-18.el9_8.10:2.85-18.el9_8.10:2.85-18.el9_8.10:2.85-18.el9_8.10:2.85-18.el9_8.1Exploitability
AV:AAC:LPR:NUI:NScope
S:UImpact
C:HI:HA:H8.8/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H