Critical Security Vulnerabilities (6 CVEs) Announced for Dnsmasq - Patches Available
By
chizhik-pyzhik
Right out the toaster. Reliable, with some real depth.
Summary
A critical security announcement from Simon Kelley, the maintainer of dnsmasq, regarding six serious CVEs (security vulnerabilities) being released by CERT on May 11, 2026. The vulnerabilities are long-standing bugs affecting virtually all non-ancient versions of dnsmasq. The vulnerabilities were pre-disclosed to vendors, who are expected to release patched versions. Patches and details are available on the project's website, and a new release (2.92rel2) has been made available.
Key quotes
· 3 pulledToday, 11th May 2026 CERT is releasing a set of six CVEs for serious security vulnerabilities in dnsmasq.
These are all long-standing bugs which apply to pretty much all non-ancient versions.
The CVE has been pre-disclosed to vendors, so hopefully they will be releasing patched versions of their dnsmasq packages in a timely manner.
Article URL: https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html
Comments URL: https://news.ycombinator.com/item?id=48112042
Points: 12
# Comments: 0
You might also wanna read
How a botnet abused my open source project's cloud version to phish 14,000 people
The author, who runs an open source project management tool called Kaneo, discovered that a botnet had abused the hosted cloud version of th
AI security audit of FreeBSD kernel reveals 15 bugs including RCEs and a hypervisor escape
An AI audit of FreeBSD uncovered 15 kernel bugs, including 3 remote code execution vulnerabilities, 5 local privilege escalation flaws, and

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Composer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoComposer and Packagist Introduce New Supply Chain Security Measures After PHP Ecosystem Attacks
Composer and Packagist.org are implementing new security measures to combat rising software supply chain attacks targeting the PHP open-sour
blog.packagist.com·4d agoCritical "BadHost" vulnerability in Starlette framework puts millions of AI agents at risk
A critical vulnerability called "BadHost" has been discovered in Starlette, an open source ASGI framework with 325 million weekly downloads.
arstechnica.com·5d ago