Vulnerabilities · 126 days ago
dnsmasq is not just a crash-prone service here. The same package can sit in front of DNS trust and DHCPv6 on small networks and embedded hosts, so one advisory now covers both remote cache poisoning and, in some setups, local privilege escalation.
The release fixes six flaws in dnsmasq 2.92rel2. The set includes heap overflows, heap corruption, out-of-bounds reads and writes, an infinite loop, and input-validation failures that can enable DNS cache poisoning, information disclosure, denial of service, source-check bypass, and possible local root through DHCPv6.
That mix matters because a compromised dnsmasq instance can do more than crash a resolver. It can rewrite answers users and devices trust, and on systems that expose DHCPv6 handling it can also become a foothold for host compromise.
CVEs in this update
6 CVEs
Across dnsmasq, azl3 dnsmasq 2.90-1 on Azure Linux 3.0, azl3 dnsmasq 2.92-1 on Azure Linux 3.0.
0 critical · 2 high · 2 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-4892 · 8.4 HIGH
1 source covering this story
Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root - Help Net Security
Six dnsmasq vulnerabilities allow DNS cache poisoning, info leaks, DoS, and local root via DHCPv6.
Part of the PlainSec briefing for 2026-05-13