Description:
The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.
Security Fix(es):
* dnsmasq: dnsmasq: heap buffer overflow in cache via NAME_ESCAPE expansion (CVE-2026-2291)
* dnsmasq: NSEC bitmap parsing infinite loop (CVE-2026-4890)
* dnsmasq: RRSIG rdlen underflow leading to heap OOB read (CVE-2026-4891)
* dnsmasq: DHCPv6 CLID buffer overflow in helper process (CVE-2026-4892)
* dnsmasq: Broken ECS source validation bypass (CVE-2026-4893)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
dnsmasq-2.85-18.el9_8.1.aarch64.rpm |
d29ee47c61111e1afe8bccf7afdd7e7cd481d18d05d525c770f77ddfbcf56c4b |
| aarch64 |
dnsmasq-utils-2.85-18.el9_8.1.aarch64.rpm |
e4db1c8e6a2c6386c714626d4de65995ba2302c5bf425b337066afca1acf21d3 |
| ppc64le |
dnsmasq-2.85-18.el9_8.1.ppc64le.rpm |
1f58632fc9724c87a1bc2ec13ac0d34c8a986c8f8a2176512807a04a574c6d45 |
| ppc64le |
dnsmasq-utils-2.85-18.el9_8.1.ppc64le.rpm |
ae864df01d23ac5cc369e77bb2bd5aa65f82342a927fadd6c3244822554a5554 |
| s390x |
dnsmasq-2.85-18.el9_8.1.s390x.rpm |
b5a8cd83c1de7204c7dfff1c24405bb880faca372e5fc8432882a4c2dadce2b8 |
| s390x |
dnsmasq-utils-2.85-18.el9_8.1.s390x.rpm |
be76a65d9cf221aae15bb0efb25a38900640252db394cc10681e1499eb69ab41 |
| x86_64 |
dnsmasq-utils-2.85-18.el9_8.1.x86_64.rpm |
946d3104b4749bf2928f28d028455ca0e725145e9c0f746300c17bfbf8d1246f |
| x86_64 |
dnsmasq-2.85-18.el9_8.1.x86_64.rpm |
a63eb39966ca6c203df9be696ca73c32c522290560e0f4604157601713265dce |