|
|
Log in / Subscribe / Register

Oracle alert ELSA-2026-19158 (dnsmasq)

From:  Errata Announcements for Oracle Linux via El-errata <el-errata@oss.oracle.com>
To:  el-errata@oss.oracle.com
Subject:  [El-errata] ELSA-2026-19158 Important: Oracle Linux 10 dnsmasq security update
Date:  Fri, 17 Jul 2026 09:56:20 -0700
Message-ID:  <mailman.326.1784307392.18.el-errata@oss.oracle.com>

Oracle Linux Security Advisory ELSA-2026-19158 http://linux.oracle.com/errata/ELSA-2026-19158.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: dnsmasq-2.90-7.el10_2.x86_64.rpm dnsmasq-utils-2.90-7.el10_2.x86_64.rpm aarch64: dnsmasq-2.90-7.el10_2.aarch64.rpm dnsmasq-utils-2.90-7.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/dnsmasq-2.90-7.e... Related CVEs: CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 Description of changes: [2.90-7] - Prevent overflow in extract_name function (CVE-2026-2291) - Prevent DoS in DNSSEC validation (CVE-2026-4890) - Prevent out-of-bounds read in DNSSEC validation (CVE-2026-4891) - Prevent out-of-bounds write in DHCPv6 server (CVE-2026-4892) - Prevent source check avoidance by RFC 7871 client-subnet (CVE-2026-4893) - Prevent out-of-bounds read in extract_addresses (CVE-2026-5172) [2.90-6] - Prevent heap buffer overflow in cache via NAME_ESCAPE expansion (CVE-2026-2291) _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds