CVE-2026-2291
dnsmasq
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
- CVSS
- 7.3
- EPSS
- 0.92% 56.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.12