VYPR

rpm package

opensuse/dnsmasq&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/dnsmasq&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2026-12725MedJun 22, 2026
    affected < 2.93-160000.1.1fixed 2.93-160000.1.1

    A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker

  • CVE-2026-2291HigMay 11, 2026
    affected < 2.93-160000.1.1fixed 2.93-160000.1.1

    dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

  • CVE-2026-6507HigApr 17, 2026
    affected < 2.93-160000.1.1fixed 2.93-160000.1.1

    A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, ca