Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1490

NIXPKGS-2026-1490
published 1 month, 2 weeks ago
updated 1 month, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 references
  • @LeSuisse ignored package prometheus-dnsmasq-exporter
  • @LeSuisse ignored maintainer @fpletz maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
CVE-2026-5172

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

Affected products

dnsmasq
  • ==2.92rel2

Matching in nixpkgs

pkgs.dnsmasq

Integrated DNS, DHCP and TFTP server for small networks

  • nixos-unstable 2.92
    • nixpkgs-unstable 2.92
    • nixos-unstable-small 2.92
Ignored packages (1)

Package maintainers

Ignored maintainers (1)