- What: Security update for dnsmasq
- Impact: Addresses multiple vulnerabilities in a DNS forwarder and DHCP server
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6264-1] dnsmasq security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6264-1] dnsmasq security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Mon, 11 May 2026 19:11:56 +0000 Message-id: <[🔎] agIp_Bzi4eXjeGfy@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6264-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 11, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dnsmasq CVE ID : CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 Multiple security vulnerabilities have been discovered in Dnsmasq, a lightweight DNS forwarder and DHCP server, which could result in cache poisoning, bypass of security controls, denial of service or local privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 2.90-4~deb12u2. For the stable distribution (trixie), these problems have been fixed in version 2.91-1+deb13u1. We recommend that you upgrade your dnsmasq packages. For the detailed security status of dnsmasq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dnsmasq Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoCKQcACgkQEMKTtsN8 TjYaSQ//TZ3t3Pym5FoVz4321Nit6/MMIE8TCNMb9OPKyMz/TBDgPvKdZ8atYWlP cB5NivpqnA6UMatq02C2wCWXiVTJ2uzPEz7ZpD2wzpbkVgQ0ffsPB8g1BROGzpKw NqlETrlboaAdCfaSPP1xgniHAs4bNjJmBhdK5cLEqtQT4arF2pGL8ETetmPiMIOO 5V1k5pafK/1Zb5A0Ehcuxi81cKlz+3xZUKz23iPXynW4qpb5Jetr1n6NCqJZ+Fof edg5IFf7xFoDVEK0MNYoNaSJXE8T/lqJ0NQ34C5+COHY1miUmcoIcY40XW4pygfu 94zWUG7HrNU3O+JCrzbuPiX2NOO3d5GCTY1V/oMxa+6UciXbWzNo4ORWfDVidqD9 Hq9gYQ/4oAJxBCdZrhKc2UteqbvbhPw+z5A8WvRl4AGjZezpcxXFXgrV6ws4mD9P VNPM5IHAHbrb8ZLafuN/qe6nL4tO927tSDJcoEjnLSCvd8xKsKfw82qq+5vIVfZ0 6X792glxJqrojN7CJAsj60n9PYWAqazce2xiPMmMrvokvLfAbJUddCvLpWWjrqqv aQsTAzw0Fxdz4KJ/GTllYeiAS95yo4M2H810Mg7ioWO79+WlhGy9Y2duuu4/u5hQ SQOWH2IpOL0C9u5SzL7qvK06G54jgSizQ7CWfx+Tr3d4v6ZHs1w= =B6xe -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6263-1] libpng1.6 security update Previous by thread: [SECURITY] [DSA 6263-1] libpng1.6 security update Index(es): Date Thread