VYPR
High severity7.3NVD Advisory· Published May 11, 2026· Updated Jul 20, 2026

CVE-2026-2291

CVE-2026-2291

Description

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11

Patches

Vulnerability mechanics

References

8

News mentions

2