A heap buffer overflow in Dnsmasq tracked as CVE-2026-2291 can be triggered when the resolver processes malicious DNS replies from an upstream DNS server, allowing memory corruption, false cache entry injection, DNS redirection, and denial of service. The flaw affects code introduced in release 2.73 and is tied to unsafe strcpy() use during cache insertion after extract_name() converts DNS names from wire format into C strings, where escaped names can exceed the 1,025-byte bigname heap buffer.
Researchers reported practical exploitation against OpenWRT 24.10.4 configured to use a malicious upstream resolver, using crafted requests and CNAME chains to corrupt the bigname free list, obtain a write-what-where primitive, and overwrite a function pointer in musl ld.so to gain instruction-pointer control. The issue was fixed on 11 May 2026 in versions 2.92rel2 and 2.93, and public reporting warns that exposed deployments could face DNS hijacking or, under the demonstrated conditions, full remote code execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
An oss-sec mailing list post described CVE-2026-2291 as enabling heap buffer overflow exploitation that could inject false DNS cache entries, redirect DNS queries to attacker-controlled IP addresses, or cause denial of service. The post also referenced Exodus Intelligence's separate RCE analysis.
Exodus Intelligence published technical details for CVE-2026-2291, showing how the bug can overflow the bigname heap buffer and be exploited. The analysis demonstrated practical remote code execution against an OpenWRT 24.10.4 target configured to use a malicious upstream DNS server.
The vulnerable heap buffer overflow condition tied to CVE-2026-2291 was introduced in Dnsmasq release 2.73, in the cache insertion path using unsafe strcpy() handling of expanded DNS names.
On 2026-05-11, the heap buffer overflow vulnerability CVE-2026-2291 was fixed in Dnsmasq versions 2.92rel2 and 2.93. The flaw could be triggered while processing malicious DNS replies from an upstream DNS server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
blog.exodusintel.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.