CVE-2026-4890Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-11); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-27: 105-1105-1305-1405-27
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-131
Disclosure1
2026-05-141
Patch1
2026-05-271
Patch1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    Disclosure

    Dnsmasqに複数のメモリ脆弱性。CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172の6件。CVE-2026-4892はDHCPv6パケットでのroot権限任意コード実行。他の影響はキャッシュポイズニング、DoS、情報漏洩。 https://securityonline.info/multiple-memory-flaws-in-dnsmasq-threaten-millions-of-connected-devices/

    Post summary

    The article reveals six memory vulnerabilities in dnsmasq, including CVE‑2026‑4892 that enables root‑privileged code execution via DHCPv6 packets, while the other flaws may cause cache poisoning, DoS, or information leakage.

    010521.2K
    7.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4890 A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. https://www.cve.org/CVERecord?id=CVE-2026-4890

    Post summary

    This text announces CVE‑2026‑4890, a DNSSEC validation denial‑of‑service flaw in dnsmasq that can be triggered by crafted DNS packets; no proof‑of‑concept, exploit code, or mitigation details are provided.

    01001376
    57.5K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-4890 isn’t a “Windows bug”… it’s just another DNS bomb hitting your mixed fleet. If Teams can’t reach the resolver, productivity dies. Patch shared dnsmasq builds. https://windowsforum.com/threads/cve-2026-4890-dnsmasq-dnssec-dos-windows-teams-must-patch-shared-dns.420067/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #DenialOfService #Dnssec #Dnsmasq https://t.co/lQRcl1xb7e

    Post summary

    CVE-2026-4890 is a DNS bomb denial‑of‑service affecting Teams; patched dnsmasq builds are recommended to mitigate the issue.

    0000057
    1.1K followersView on X
  • Samet@sametating
    Patch

    dnsmasq'e 6 cve birden: - CVE-2026-4890/4891/4892/4893 + 2 tane daha - "eski olmayan tüm sürümleri" etkiliyor - ai tabanlı güvenlik araştırmasıyla keşfedildi - fix: 2.92rel2, 2.93 de yolda - her linux sisteminden ev routerina kadar https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html

    Post summary

    The post announces six newly discovered CVEs in dnsmasq, highlights that the latest release 2.92rel2 includes a fix and 2.93 is forthcoming, and urges all Linux-based users, from general systems to home routers, to update.

    0000035
    5 followersView on X

Explore more