Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1489

NIXPKGS-2026-1489
published 1 month, 2 weeks ago
updated 1 month, 2 weeks ago by @LeSuisse Activity log
CVE-2026-2291

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Affected products

dnsmasq
  • ==2.92rel2

Matching in nixpkgs

pkgs.dnsmasq

Integrated DNS, DHCP and TFTP server for small networks

  • nixos-unstable 2.92
    • nixpkgs-unstable 2.92
    • nixos-unstable-small 2.92
Ignored packages (1)

Package maintainers

Ignored maintainers (1)