HomeDefectsLIN1021-25598
Fixed

LIN1021-25598 : Security Advisory - dnsmasq - CVE-2026-2291

Created: May 12, 2026    Updated: Jun 8, 2026
Resolved Date: Jun 8, 2026
Found In Version: 10.21.20.2
Fix Version: 10.21.20.27
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

CVEs