CERT/CC and the dnsmasq maintainer disclosed six vulnerabilities in dnsmasq that affect most supported, non-legacy versions and can lead to DNS cache poisoning, denial of service, information disclosure, security-control bypass, heap manipulation, and local privilege escalation. The issues are tracked as CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, and CVE-2026-5172, and stem from flaws in memory safety, input validation, DNSSEC handling, DHCPv6, and DNS parsing. Several attack paths are remote via crafted DNS packets or malformed DNS responses, while CVE-2026-4892 is a heap-based out-of-bounds write in DHCPv6 that can let a local attacker execute arbitrary code as root with a crafted packet.
Maintainer Simon Kelley released dnsmasq 2.92rel2 with backported fixes for the stable branch and indicated the fixes are incorporated into version 2.93, which CERT/CC lists as fixed. Vendor remediation followed quickly, including a Debian security update (DSA 6264-1), and additional vendors were expected to publish patched packages. The disclosure drew attention because dnsmasq is widely deployed in routers, Linux systems, and embedded environments, making prompt patching important wherever the service is exposed to untrusted DNS or local network traffic.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA-6264-1 to provide patched dnsmasq packages for the disclosed vulnerabilities. This reflected downstream vendor remediation following the coordinated disclosure.
The CVE record for CVE-2026-4892 was updated on May 11, 2026 with a description of a heap-based out-of-bounds write in dnsmasq's DHCPv6 implementation that could allow local root code execution via a crafted DHCPv6 packet. References and a CVSS v3.1 vector were also added.
On May 11, 2026, CERT/CC publicly disclosed six dnsmasq vulnerabilities: CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, and CVE-2026-5172. The issues included DNS cache poisoning, denial of service, information disclosure, security-control bypass, and local privilege escalation.
Dnsmasq maintainer Simon Kelley announced release 2.92rel2 for the stable 2.92 branch with patches for the newly disclosed vulnerabilities. He also indicated fixes would be incorporated into the upcoming 2.93 release cycle.
CERT/CC published advisory VU#471747 covering multiple dnsmasq flaws that could enable attacker-controlled DNS redirection, privilege escalation, and heap manipulation. The advisory later served as the central reference for the coordinated disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
bugflation.com
Open sourceseclists.org
Open sourcehelpnetsecurity.com
Open sourcelists.thekelleys.org.uk
Open sourceseclists.org
Open sourceopennet.me
Open sourcekb.cert.org
Open sourcekb.cert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.