Red Hat Security Advisory: dnsmasq security update
Multiple security vulnerabilities have been identified in the dnsmasq package version 2.85-17.el9_6.1 used in Red Hat Enterprise Linux 9.6 Extended Update Support. These include heap buffer overflow, infinite loop in NSEC bitmap parsing, heap out-of-bounds read, DHCPv6 client identifier buffer overflow, and source validation bypass issues. Red Hat has issued an important security advisory with updates to address these issues. The advisory covers five CVEs: CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, and CVE-2026-4893. The vulnerabilities affect dnsmasq versions specifically identified as 2.85-17.el9_6.1. Red Hat provides updated packages to fix these issues.
AI Analysis
Technical Summary
The dnsmasq package version 2.85-17.el9_6.1 for Red Hat Enterprise Linux 9.6 Extended Update Support contains multiple security vulnerabilities. These include a heap buffer overflow triggered via NAME_ESCAPE expansion (CVE-2026-2291), an infinite loop in NSEC bitmap parsing (CVE-2026-4890), a heap out-of-bounds read caused by RRSIG rdlen underflow (CVE-2026-4891), a DHCPv6 client identifier buffer overflow in the helper process (CVE-2026-4892), and a broken ECS source validation bypass (CVE-2026-4893). Red Hat has issued an important security advisory (RHSA-2026:20589) that provides updated dnsmasq packages to address these vulnerabilities. The advisory applies to Red Hat Enterprise Linux 8 and 9 Extended Update Support variants across multiple architectures. No CVSS scores are provided in the advisory. No known exploits in the wild have been reported. The vendor advisory includes instructions for applying the update and references to the CVE details.
Potential Impact
These vulnerabilities could allow an attacker to cause denial of service conditions (e.g., infinite loops), memory corruption (heap buffer overflow and out-of-bounds reads), and bypass of source validation mechanisms in dnsmasq. Such issues may lead to crashes or potentially enable further exploitation depending on the environment and usage of dnsmasq. The advisory rates the overall impact as Important (high severity). No known active exploitation has been reported at this time.
Mitigation Recommendations
Red Hat has released updated dnsmasq packages that address these vulnerabilities. Users of affected versions (=2.85-17.el9_6.1) should apply the security update as described in Red Hat advisory RHSA-2026:20589 and the linked article https://access.redhat.com/articles/11258. Applying the official update is the recommended and effective mitigation. No alternative workarounds or temporary fixes are indicated in the advisory.
Red Hat Security Advisory: dnsmasq security update
Description
Multiple security vulnerabilities have been identified in the dnsmasq package version 2.85-17.el9_6.1 used in Red Hat Enterprise Linux 9.6 Extended Update Support. These include heap buffer overflow, infinite loop in NSEC bitmap parsing, heap out-of-bounds read, DHCPv6 client identifier buffer overflow, and source validation bypass issues. Red Hat has issued an important security advisory with updates to address these issues. The advisory covers five CVEs: CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, and CVE-2026-4893. The vulnerabilities affect dnsmasq versions specifically identified as 2.85-17.el9_6.1. Red Hat provides updated packages to fix these issues.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The dnsmasq package version 2.85-17.el9_6.1 for Red Hat Enterprise Linux 9.6 Extended Update Support contains multiple security vulnerabilities. These include a heap buffer overflow triggered via NAME_ESCAPE expansion (CVE-2026-2291), an infinite loop in NSEC bitmap parsing (CVE-2026-4890), a heap out-of-bounds read caused by RRSIG rdlen underflow (CVE-2026-4891), a DHCPv6 client identifier buffer overflow in the helper process (CVE-2026-4892), and a broken ECS source validation bypass (CVE-2026-4893). Red Hat has issued an important security advisory (RHSA-2026:20589) that provides updated dnsmasq packages to address these vulnerabilities. The advisory applies to Red Hat Enterprise Linux 8 and 9 Extended Update Support variants across multiple architectures. No CVSS scores are provided in the advisory. No known exploits in the wild have been reported. The vendor advisory includes instructions for applying the update and references to the CVE details.
Potential Impact
These vulnerabilities could allow an attacker to cause denial of service conditions (e.g., infinite loops), memory corruption (heap buffer overflow and out-of-bounds reads), and bypass of source validation mechanisms in dnsmasq. Such issues may lead to crashes or potentially enable further exploitation depending on the environment and usage of dnsmasq. The advisory rates the overall impact as Important (high severity). No known active exploitation has been reported at this time.
Mitigation Recommendations
Red Hat has released updated dnsmasq packages that address these vulnerabilities. Users of affected versions (=2.85-17.el9_6.1) should apply the security update as described in Red Hat advisory RHSA-2026:20589 and the linked article https://access.redhat.com/articles/11258. Applying the official update is the recommended and effective mitigation. No alternative workarounds or temporary fixes are indicated in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20589
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-4890","CVE-2026-4891","CVE-2026-4892","CVE-2026-4893"]
- Cvss Version
- null
Threat ID: 6a16097ce29bf47b50648826
Added to database: 05/26/2026, 20:58:36 UTC
Last enriched: 07/31/2026, 01:37:57 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.