Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19158 http://linux.oracle.com/errata/ELSA-2026-19158.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: dnsmasq-2.90-7.el10_2.x86_64.rpm dnsmasq-utils-2.90-7.el10_2.x86_64.rpm aarch64: dnsmasq-2.90-7.el10_2.aarch64.rpm dnsmasq-utils-2.90-7.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/dnsmasq-2.90-7.el10_2.src.rpm Related CVEs: CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 Description of changes: [2.90-7] - Prevent overflow in extract_name function (CVE-2026-2291) - Prevent DoS in DNSSEC validation (CVE-2026-4890) - Prevent out-of-bounds read in DNSSEC validation (CVE-2026-4891) - Prevent out-of-bounds write in DHCPv6 server (CVE-2026-4892) - Prevent source check avoidance by RFC 7871 client-subnet (CVE-2026-4893) - Prevent out-of-bounds read in extract_addresses (CVE-2026-5172) [2.90-6] - Prevent heap buffer overflow in cache via NAME_ESCAPE expansion (CVE-2026-2291) _______________________________________________ El-errata mailing list
An update that solves two vulnerabilities can now be installed.. # Security update for dnsmasq Announcement ID: SUSE-SU-2026:3028-1 Release Date: 2026-07-15T09:51:44Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAPApplications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3028=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3028=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3028=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3028=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3028=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3028=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3028=1 * SUSE LinuxEnterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3028=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3028=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) *dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-utils-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * dnsmasq-utils-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 . This update for dnsmasq addresses crucial issues including a buffer overflow and out-of-bounds read, important to secure.. dnsmasq security,SUSE update, buffer overflow fix, openSUSE patches. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Dnsmasq.. ========================================================================== Ubuntu Security Notice USN-8542-1 July 14, 2026 dnsmasq vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Dnsmasq. Software Description: - dnsmasq: Small caching DNS proxy and DHCP/TFTP server Details: Yiwei Hou discovered that Dnsmasq incorrectly handled logging of DS or DNSKEY. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-12725) It was discovered that Dnsmasq incorrectly validated the length of fixed-length DNS record fields when parsing NS section records. A remote attacker could possibly use this issue to cause Dnsmasq to read out of bounds, possibly exposing sensitive information. (CVE-2026-12969) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS dnsmasq 2.92-1ubuntu0.4 dnsmasq-base 2.92-1ubuntu0.4 dnsmasq-base-lua 2.92-1ubuntu0.4 dnsmasq-utils 2.92-1ubuntu0.4 Ubuntu 24.04 LTS dnsmasq 2.90-2ubuntu0.4 dnsmasq-base 2.90-2ubuntu0.4 dnsmasq-base-lua 2.90-2ubuntu0.4 dnsmasq-utils 2.90-2ubuntu0.4 Ubuntu 22.04 LTS dnsmasq 2.90-0ubuntu0.22.04.4 dnsmasq-base 2.90-0ubuntu0.22.04.4 dnsmasq-base-lua 2.90-0ubuntu0.22.04.4 dnsmasq-utils 2.90-0ubuntu0.22.04.4 Ubuntu 20.04 LTS dnsmasq 2.90-0ubuntu0.20.04.1+esm3 Available with Ubuntu Pro dnsmasq-base 2.90-0ubuntu0.20.04.1+esm3 Available with Ubuntu Pro dnsmasq-base-lua 2.90-0ubuntu0.20.04.1+esm3 Available with Ubuntu Pro dnsmasq-utils 2.90-0ubuntu0.20.04.1+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS dnsmasq 2.90-0ubuntu0.18.04.1+esm4 Available with Ubuntu Pro dnsmasq-base 2.90-0ubuntu0.18.04.1+esm4 Available with Ubuntu Pro dnsmasq-base-lua 2.90-0ubuntu0.18.04.1+esm4 Available with Ubuntu Pro dnsmasq-utils 2.90-0ubuntu0.18.04.1+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS dnsmasq 2.90-0ubuntu0.16.04.1+esm4 Available with Ubuntu Pro dnsmasq-base 2.90-0ubuntu0.16.04.1+esm4 Available with Ubuntu Pro dnsmasq-base-lua 2.90-0ubuntu0.16.04.1+esm4 Available with Ubuntu Pro dnsmasq-utils 2.90-0ubuntu0.16.04.1+esm4 Available with Ubuntu Pro After a standard system update you need to restart dnsmasq to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8542-1 CVE-2026-12725, CVE-2026-12969 Package Information: https://launchpad.net/ubuntu/+source/dnsmasq/2.92-1ubuntu0.4 https://launchpad.net/ubuntu/+source/dnsmasq/2.90-2ubuntu0.4 https://launchpad.net/ubuntu/+source/dnsmasq/2.90-0ubuntu0.22.04.4 . Resolve critical security issues in Dnsmasq for multiple Ubuntu LTS versions to prevent potential information exposure or denial of service.. Dnsmasq Security Advisories, Ubuntu LTS Patches, dnsmasq Exploit Fixes. . Severity: Critical. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22496-1 Release Date: 2026-06-29T07:41:58Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). Changes for dnsmasq: * CVE-2026-12725, bsc#1268764: Heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies. * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. * CVE-2026-2291: Rework storageallocation for domain names. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-utils-debuginfo-2.93-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsmasq-utils-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-debuginfo-2.93-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 . Critical security update for dnsmasq addresses three vulnerabilities affecting SUSE systems to enhance overall protection.. dnsmasq update, SUSE security, software vulnerabilities, linux patch management. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22454-1 Release Date: 2026-06-30T11:27:04Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-604=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-slfo.1.1_1.1 * dnsmasq-debuginfo-2.93-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html *https://bugzilla.suse.com/show_bug.cgi?id=1268764 . Discover the update for dnsmasq addressing important security risks with actionable instructions for SUSE users.. dnsmasq security, SUSE update, important patch, buffer overflow risk. . Severity: Important. LinuxSecurity.com Team
An update that solves 3 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for dnsmasq ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21192-1 Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has one bug fix can now be installed. Description: This update for dnsmasq fixes the following issues Update to 2.93: - CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). Changes for dnsmasq: * CVE-2026-12725, bsc#1268764: Heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies. * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. * CVE-2026-2291: Rework storage allocation for domain names. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively youcan run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1102=1 Package List: - openSUSE Leap 16.0: dnsmasq-2.93-160000.1.1 dnsmasq-utils-2.93-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html . An important security update for openSUSE addressing three vulnerabilities in dnsmasq, improving system security and stability.. dnsmasq security, opensuse update, system vulnerability, openSUSE Leap vulnerability. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19373 http://linux.oracle.com/errata/ELSA-2026-19373.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: dnsmasq-2.85-18.el9_8.1.x86_64.rpm dnsmasq-utils-2.85-18.el9_8.1.x86_64.rpm aarch64: dnsmasq-2.85-18.el9_8.1.aarch64.rpm dnsmasq-utils-2.85-18.el9_8.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/dnsmasq-2.85-18.el9_8.1.src.rpm Related CVEs: CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 Description of changes: [2.85-18.1] - Prevent overflow in extract_name function (CVE-2026-2291) - Prevent DoS in DNSSEC validation (CVE-2026-4890) - Prevent out-of-bounds read in DNSSEC validation (CVE-2026-4891) - Prevent out-of-bounds write in DHCPv6 server (CVE-2026-4892) - Prevent source check avoidance by RFC 7871 client-subnet (CVE-2026-4893) _______________________________________________ El-errata mailing list
An update that solves seven vulnerabilities can now be installed.. # Security update for dnsmasq Announcement ID: SUSE-SU-2026:2458-1 Release Date: 2026-06-18T15:54:29Z Rating: important References: * bsc#1258251 * bsc#1262487 * bsc#1265001 * bsc#1265002 * bsc#1265003 * bsc#1265004 * bsc#1265006 Cross-References: * CVE-2026-2291 * CVE-2026-4890 * CVE-2026-4891 * CVE-2026-4892 * CVE-2026-4893 * CVE-2026-5172 * CVE-2026-6507 CVSS scores: * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-4890 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4890 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4891 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4891 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4892 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4892 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4893 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4893 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5172 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5172 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAPApplications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-2291: VU#471747: dnsmasq can be abused to record false cached data enabling DoS or attacker redirect (bsc#1258251). * CVE-2026-4890: DoS vulnerability in the DNSSEC validation (bsc#1265001). * CVE-2026-4891: heap-based out-of-bounds read vulnerability in the DNSSEC validation (bsc#1265002). * CVE-2026-4892: heap-based out-of-bounds write vulnerability in the DHCPv6 implementation (bsc#1265003). * CVE-2026-4893: information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks (bsc#1265004). * CVE-2026-5172: buffer overflow in dnsmasq's extract_addresses() function (bsc#1265006). * CVE-2026-6507: out-of-bounds write in DHCP BOOTREPLY processing can lead to denial of service (bsc#1262487). Changes for dnsmasq: * Update to security release 2.92rel2. * Fix setting of compile time options from the spec file. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2458=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2458=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.92rel2-18.27.1 * dnsmasq-2.92rel2-18.27.1 * dnsmasq-debugsource-2.92rel2-18.27.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dnsmasq-debuginfo-2.92rel2-18.27.1 * dnsmasq-2.92rel2-18.27.1 * dnsmasq-debugsource-2.92rel2-18.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2291.html *https://www.suse.com/security/cve/CVE-2026-4890.html * https://www.suse.com/security/cve/CVE-2026-4891.html * https://www.suse.com/security/cve/CVE-2026-4892.html * https://www.suse.com/security/cve/CVE-2026-4893.html * https://www.suse.com/security/cve/CVE-2026-5172.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1258251 * https://bugzilla.suse.com/show_bug.cgi?id=1262487 * https://bugzilla.suse.com/show_bug.cgi?id=1265001 * https://bugzilla.suse.com/show_bug.cgi?id=1265002 * https://bugzilla.suse.com/show_bug.cgi?id=1265003 * https://bugzilla.suse.com/show_bug.cgi?id=1265004 * https://bugzilla.suse.com/show_bug.cgi?id=1265006 . Important security update addresses multiple vulnerabilities in dnsmasq, ensuring SUSE systems remain secure and stable.. dnsmasq vulnerabilities, SUSE security update, important patches, DNSSEC vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.