{"id":"CLEANSTART-2026-KY78316","summary":"dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-...","details":"Multiple security vulnerabilities affect the dnsmasq package. dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. See references for individual vulnerability details.","modified":"2026-09-18T12:17:37.448971786Z","published":"2026-09-04T00:59:50.930698Z","withdrawn":"2026-09-18T11:59:01.768079Z","upstream":["CVE-2017-13704","CVE-2017-14491","CVE-2017-14492","CVE-2017-14493","CVE-2017-14494","CVE-2017-14495","CVE-2017-14496","CVE-2017-15107","CVE-2019-14834","CVE-2020-25681","CVE-2020-25682","CVE-2020-25683","CVE-2020-25684","CVE-2020-25685","CVE-2020-25686","CVE-2020-25687","CVE-2021-3448","CVE-2022-0934","CVE-2023-28450","CVE-2023-50387","CVE-2023-50868","CVE-2026-2291","CVE-2026-4890","CVE-2026-4891","CVE-2026-4892","CVE-2026-4893","CVE-2026-5172"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-KY78316.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-13704"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14491"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14492"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14493"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14494"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14495"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-14496"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2017-15107"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2019-14834"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25681"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25682"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25683"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25684"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25685"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25686"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2020-25687"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2021-3448"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2022-0934"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2023-28450"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2023-50387"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2023-50868"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-2291"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-4890"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-4891"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-4892"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-4893"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-5172"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-13704"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14491"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14492"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14493"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14494"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14495"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14496"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15107"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14834"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25681"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25682"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25683"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25684"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25685"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25686"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25687"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3448"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0934"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28450"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50387"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50868"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2291"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4890"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4891"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4892"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4893"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5172"}],"affected":[{"package":{"name":"dnsmasq","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.92_p2-r0"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-KY78316.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}