NIXPKGS-2026-1490
GitHub issue
published 1 month, 2 weeks ago
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored
- @LeSuisse ignored package prometheus-dnsmasq-exporter
- @LeSuisse ignored maintainer @fpletz maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
CVE-2026-5172
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
References
Ignored references (2)
Affected products
dnsmasq
- ==2.92rel2
Matching in nixpkgs
Ignored packages (1)
pkgs.prometheus-dnsmasq-exporter
Dnsmasq exporter for Prometheus
Package maintainers
Ignored maintainers (1)
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>