This update for dnsmasq fixes the following issues:
Update to version 2.86
- CVE-2021-3448: fixed outgoing port used when --server is used with an
interface name. (bsc#1183709)
- CVE-2020-14312: Set --local-service by default (bsc#1173646).
- Open inotify socket only when used (bsc#1180914).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1426=1
- openSUSE Leap 15.2 (i586 x86_64):
dnsmasq-2.86-lp152.7.6.1
dnsmasq-debuginfo-2.86-lp152.7.6.1
dnsmasq-debugsource-2.86-lp152.7.6.1
dnsmasq-utils-2.86-lp152.7.6.1
dnsmasq-utils-debuginfo-2.86-lp152.7.6.1
https://www.suse.com/security/cve/CVE-2020-14312.html
https://www.suse.com/security/cve/CVE-2021-3448.html
https://bugzilla.suse.com/1173646
https://bugzilla.suse.com/1180914
https://bugzilla.suse.com/1183709
Get the latest Linux and open source security news straight to your inbox.