{"id":"SUSE-SU-2026:21626-1","summary":"Security update for dnsmasq","details":"This update for dnsmasq fixes the following issues:\n\nSecurity issues:\n\n- CVE-2023-49441: integer overflow via forward_query (bsc#1226091).\n- CVE-2026-2291: VU#471747: dnsmasq can be abused to record false cached data enabling DoS or attacker redirect\n  (bsc#1258251).\n\nNon security issue:\n\n- Reintroduce nogroup (bsc#1235517).\n","modified":"2026-05-16T18:24:14.194680319Z","published":"2026-05-12T09:38:42Z","related":["CVE-2023-49441","CVE-2026-2291"],"upstream":["CVE-2023-49441","CVE-2026-2291"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621626-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235834"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258251"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-49441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2291"}],"schema_version":"1.7.5"}