CLEANSTART-2026-KY78316
Dashboard / Vulnerabilities / CLEANSTART-2026-KY78316
CLEANSTART-2026-KY78316
Summary: dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-...
Details: Multiple security vulnerabilities affect the dnsmasq package. dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KY78316.json, https://osv.dev/vulnerability/CVE-2017-13704, https://osv.dev/vulnerability/CVE-2017-14491, https://osv.dev/vulnerability/CVE-2017-14492, https://osv.dev/vulnerability/CVE-2017-14493, https://osv.dev/vulnerability/CVE-2017-14494, https://osv.dev/vulnerability/CVE-2017-14495, https://osv.dev/vulnerability/CVE-2017-14496, https://osv.dev/vulnerability/CVE-2017-15107, https://osv.dev/vulnerability/CVE-2019-14834, https://osv.dev/vulnerability/CVE-2020-25681, https://osv.dev/vulnerability/CVE-2020-25682, https://osv.dev/vulnerability/CVE-2020-25683, https://osv.dev/vulnerability/CVE-2020-25684, https://osv.dev/vulnerability/CVE-2020-25685, https://osv.dev/vulnerability/CVE-2020-25686, https://osv.dev/vulnerability/CVE-2020-25687, https://osv.dev/vulnerability/CVE-2021-3448, https://osv.dev/vulnerability/CVE-2022-0934, https://osv.dev/vulnerability/CVE-2023-28450, https://osv.dev/vulnerability/CVE-2023-50387, https://osv.dev/vulnerability/CVE-2023-50868, https://osv.dev/vulnerability/CVE-2026-2291, https://osv.dev/vulnerability/CVE-2026-4890, https://osv.dev/vulnerability/CVE-2026-4891, https://osv.dev/vulnerability/CVE-2026-4892, https://osv.dev/vulnerability/CVE-2026-4893, https://osv.dev/vulnerability/CVE-2026-5172, https://nvd.nist.gov/vuln/detail/CVE-2017-13704, https://nvd.nist.gov/vuln/detail/CVE-2017-14491, https://nvd.nist.gov/vuln/detail/CVE-2017-14492, https://nvd.nist.gov/vuln/detail/CVE-2017-14493, https://nvd.nist.gov/vuln/detail/CVE-2017-14494, https://nvd.nist.gov/vuln/detail/CVE-2017-14495, https://nvd.nist.gov/vuln/detail/CVE-2017-14496, https://nvd.nist.gov/vuln/detail/CVE-2017-15107, https://nvd.nist.gov/vuln/detail/CVE-2019-14834, https://nvd.nist.gov/vuln/detail/CVE-2020-25681, https://nvd.nist.gov/vuln/detail/CVE-2020-25682, https://nvd.nist.gov/vuln/detail/CVE-2020-25683, https://nvd.nist.gov/vuln/detail/CVE-2020-25684, https://nvd.nist.gov/vuln/detail/CVE-2020-25685, https://nvd.nist.gov/vuln/detail/CVE-2020-25686, https://nvd.nist.gov/vuln/detail/CVE-2020-25687, https://nvd.nist.gov/vuln/detail/CVE-2021-3448, https://nvd.nist.gov/vuln/detail/CVE-2022-0934, https://nvd.nist.gov/vuln/detail/CVE-2023-28450, https://nvd.nist.gov/vuln/detail/CVE-2023-50387, https://nvd.nist.gov/vuln/detail/CVE-2023-50868, https://nvd.nist.gov/vuln/detail/CVE-2026-2291, https://nvd.nist.gov/vuln/detail/CVE-2026-4890, https://nvd.nist.gov/vuln/detail/CVE-2026-4891, https://nvd.nist.gov/vuln/detail/CVE-2026-4892, https://nvd.nist.gov/vuln/detail/CVE-2026-4893, https://nvd.nist.gov/vuln/detail/CVE-2026-5172
Affected packages
Package
Name: dnsmasq
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
