CVE-2026-2291
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
- Affected products
- Linuxmint, Rocky Linux, Ubuntu, Dnsmasq
- Fix
- Available
- CVSS 3.1
- 7.3 HIGH
- EPSS
- 0.6% (47th percentile)
- NVD status
- Awaiting Analysis
- Published
- 2026-05-11
CVE-2026-2291 at NVD
1 known exploit for CVE-2026-2291
Proof-of-concept code and exploit modules indexed by Sploitus