CVE-2026-2291: exploitation status and patch state
CVE-2026-2291 · patch available
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
Is CVE-2026-2291 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.