Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1490

NIXPKGS-2026-1490
published 3 months ago
updated 3 months ago by @LeSuisse Activity log
CVE-2026-5172

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

Affected products

dnsmasq
  • ==2.92rel2

Matching in nixpkgs

pkgs.dnsmasq

Integrated DNS, DHCP and TFTP server for small networks

  • nixos-unstable 2.92
    • nixpkgs-unstable 2.92
    • nixos-unstable-small 2.92
Ignored packages (1)

Package maintainers

Ignored maintainers (1)