CVE-2026-2291Patch

MEDIUMCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

4.3/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-13); latest day: 1
  • 10 total mentions across 8 days

Deep dive

Activity timeline10 mentions / 8d
01223Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 3Mentions · 2026-05-14: 1Mentions · 2026-05-27: 1Mentions · 2026-07-20: 1Mentions · 2026-07-22: 1Mentions · 2026-08-06: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 2Technical Details · 2026-07-20: 1Technical Details · 2026-07-22: 1Technical Details · 2026-08-06: 105-1105-1205-1305-1405-2707-2007-2208-06
Signal classification3 categories
Patch
660.0%
Disclosure
330.0%
PoC
110.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-121
Patch1
2026-05-133
Disclosure1Patch2
2026-05-141
Patch1
2026-05-271
Disclosure1
2026-07-201
Patch1
2026-07-221
PoC1
2026-08-061
Patch1
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    dnsmasq patches 6 critical flaws (CVE-2026-2291+) enabling DNS poisoning and root access. Update your router firmware to version 2.92rel2 now! #dnsmasq #NetworkSecurity #CyberSecurity #InfoSec #RouterPatch #DNSSEC #VulnerabilityAlert #SysAdmin #IoT https://securityonline.info/multiple-memory-flaws-in-dnsmasq-threaten-millions-of-connected-devices/ https://t.co/4d8rSEwnx5

    Post summary

    The tweet highlights the discovery of six critical dnsmasq flaws and urges users to apply the 2.92rel2 firmware patch, providing technical details but no exploit code or active exploitation reports.

    030111511
    12.5K followersView on X
  • dbugs@ptdbugs
    Patch

    Heap Buffer Overflow in Dnsmasq Researchers at Exodus Intelligence analyzed a heap buffer overflow vulnerability (CVE-2026-2291 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-2291)) in the popular Dnsmasq DNS/DHCP service, which is used in OpenWrt, routers, and other network devices. When processing a response from an upstream DNS server, Dnsmasq converts domain names from DNS wire-format into C strings. Special bytes—the null byte, dot, and escape character—are replaced with escape sequences, which can significantly increase the string's length. For long DNS names, the cache uses a heap-allocated buffer, "bigname", 1025 bytes in size. However, the resulting string length is not checked before it is copied with "strcpy()". As a result, a specially crafted DNS name can overflow "bigname" and corrupt adjacent heap structures. The article describes an exploitation scenario on OpenWrt 24.10.4. An important prerequisite is that the device must use an upstream DNS server controlled by the attacker. A fully reliable exploit may also require an additional address leak to bypass memory protections. In addition to code execution, the vulnerability enables denial of service and DNS cache poisoning, redirecting clients to an attacker-controlled IP address. The bug was introduced in Dnsmasq 2.73 and fixed in versions 2.92rel2 and 2.93. Article: https://blog.exodusintel.com/2026/07/20/dnsmasq-dns-remote-heap-buffer-overflow/ #dbugs_attacks

    Post summary

    The article details a heap buffer overflow in Dnsmasq, explains the technical mechanics and impact, and notes that the issue is fixed in newer releases.

    01092981
    3.6K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Dnsmasqに複数のメモリ脆弱性。CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172の6件。CVE-2026-4892はDHCPv6パケットでのroot権限任意コード実行。他の影響はキャッシュポイズニング、DoS、情報漏洩。 https://securityonline.info/multiple-memory-flaws-in-dnsmasq-threaten-millions-of-connected-devices/

    Post summary

    An article announces six new memory vulnerabilities in dnsmasq, including CVE-2026-4892 that enables arbitrary root code execution via DHCPv6 packets, with other impacts such as cache poisoning, DoS, and information leakage.

    010521.2K
    7.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-2291: Remote heap buffer overflow in Dnsmasq allows RCE via a malicious upstream DNS server, patched in versions 2.92rel2 and 2.93 on May 11, 2026. Key details: - CVE-2026-2291 exists in Dnsmasq 2.73 through 2.92, introduced in 2015 when DNSSEC label handling expanded escaped domain name encoding but left the 1,025-byte bigname cache buffer unchecked. An unsafe strcpy() in really_insert() inside src/cache.c copies attacker-controlled name strings without bounds validation, overflowing the heap buffer. - Exploitation requires no local access: a client behind a Dnsmasq resolver queries attacker-controlled domains (http://alloc.me, http://overflow.me, http://overwrite.me) while the resolver uses a malicious upstream DNS server. The attacker shapes the heap via crafted CNAME chains, corrupts a bigname free-list pointer, and achieves a write-what-where primitive by abusing the cache allocator's own strcpy. - The exploit overwrites the VDSO_CGT32_SYM function pointer in musl http://ld.so at offset 0x812a8 from the library base, demonstrating EIP control on OpenWRT 24.10.4 (x86). Because bigname buffers are never freed through libc, heap corruption goes undetected by standard allocator mitigations. - Any network running Dnsmasq as a forwarding resolver with an untrusted or compromised upstream DNS server is in scope: home routers, enterprise DNS forwarders, embedded devices. Patch to 2.92rel2 or 2.93 immediately. #DFIR_Radar

    Post summary

    The post discloses a remote heap buffer overflow in Dnsmasq that permits RCE via a malicious upstream DNS server, emphasizes urgent patching with versions 2.92rel2/2.93, and provides detailed technical exploitation information but no PoC or evidence of active attacks.

    10020204
    1.9K followersView on X
  • Open Source Security mailing list@oss_security
    PoC

    dnsmasq: Further info on CVE-2026-2291 remote heap buffer overflow posted by a researcher https://www.openwall.com/lists/oss-security/2026/07/20/14 "how we exploited it to gain remote code execution on a OpenWRT target that is configured with a malicious upstream DNS server." Higher impact than previously known.

    Post summary

    A researcher shared a PoC demonstrating remote heap overflow RCE on dnsmasq (CVE-2026-2291) via a malicious upstream DNS server, indicating higher impact than previously known.

    00000191
    4.7K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 CVE-2026-2291 is the “DNS helper” bug that proves Windows isn’t your whole attack surface. Microsoft logging it but not patching Windows? Congrats, hybrid life: defend everything. https://windowsforum.com/threads/cve-2026-2291-dnsmasq-dns-parsing-bug-patch-focus-for-windows-hybrid-environments.420061/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsPatchManagement #DnsCachePoisoning #DnsmasqVulnerability https://t.co/nXJ1fEayRw

    Post summary

    The tweet announces Microsoft’s logging of CVE-2026-2291, noting that no patch has been released and highlighting Windows as part of the attack surface.

    0000054
    1.1K followersView on X
  • Samet@sametating
    Patch

    dnsmasq'a tek seferde 6 cve: - etkilenen: neredeyse tüm versiyon - cve-2026-2291, 4890, 4891, 4892, 4893, 5172 - uzun süredir açıkta olan bug'lar - patch: 2.92rel2 çıktı, 2.93 yolda - pi-hole, router, embedded sistemlerde çok yaygın https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

    Post summary

    Six long‑standing dnsmasq CVEs are disclosed with patches already released or coming soon. No proof of concept, exploit, or active exploitation evidence is provided.

    0000040
    5 followersView on X
  • Samet@sametating
    Patch

    dnsmasq'a tek seferde 6 cve: - cve-2026-2291/4890/4891/4892/4893/5172 - neredeyse tüm sürümleri etkiliyor, yıllardır vardı - 2.92rel2 ve 2.93rc1 ile patch geldi - router, android, kubernetes node — hepsi bunun üzerinde https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

    Post summary

    The tweet lists six dnsmasq CVEs affecting nearly all versions, with patches released for 2.92rel2 and 2.93rc1. No PoC, exploit code, or evidence of active exploitation is mentioned.

    0000047
    5 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Pi-hole releases FTL 6.6.2, patching 6 critical dnsmasq flaws (CVE-2026-2291, 4890-4893, 5172) enabling code execution and DoS on Arch, Red Hat and Ubuntu systems. https://threatcluster.io/cluster/critical-dnsmasq-vulnerabilities-patched-in-pi-hole-update-a14f367a

    Post summary

    Pi‑hole’s 6.6.2 update patches six critical dnsmasq CVEs that could allow code execution and denial‑of‑service on Arch, Red Hat, and Ubuntu systems.

    0000073
    244 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2291 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookup… https://www.cve.org/CVERecord?id=CVE-2026-2291

    Post summary

    A concise disclosure of CVE-2026-2291, describing a heap buffer overflow in dnsmasq that permits insertion of falsified DNS cache records.

    00000100
    57.5K followersView on X

Explore more