NIXPKGS-2026-1489
GitHub issue
published 1 month, 2 weeks ago
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored
- @LeSuisse ignored package prometheus-dnsmasq-exporter
- @LeSuisse ignored maintainer @fpletz maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
CVE-2026-2291
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
References
Affected products
dnsmasq
- ==2.92rel2
Matching in nixpkgs
Ignored packages (1)
pkgs.prometheus-dnsmasq-exporter
Dnsmasq exporter for Prometheus
Package maintainers
Ignored maintainers (1)
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>