Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices
ID: 29d6e669-259d-59d6-8702-cd0f41a4f9b7
STIX ID: report--29d6e669-259d-59d6-8702-cd0f41a4f9b7
Feed Name: securityonline.info
This advisory details six critical dnsmasq vulnerabilities (CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172) that enable DNS cache poisoning, DNSSEC validation failures, information disclosure, DoS via infinite loops or crashes, and a local root escalation via a crafted DHCPv6 packet; due to dnsmasq's widespread presence in home routers and IoT firmware, the report warns of broad impact and recommends immediate upgrades to dnsmasq 2.92rel2 and vendor firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
