CVE-2026-5172
EUVD-2026-2915611.05.2026, 18:16
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.90-7.el10_2 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dnsmasq |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| dnsmasq |
| ||
| dnsmasq-debuginfo |
| ||
| dnsmasq-debugsource |
| ||
| dnsmasq-utils |
| ||
| dnsmasq-utils-debuginfo |
|
Common Weakness Enumeration
References