Critical Dnsmasq Vulnerability Exposes Ubuntu Systems to Remote Attacks

Critical Dnsmasq Vulnerability Exposes Ubuntu Systems to Remote Attacks

First seen 27 May 2026, 03:40 UTC UbuntuLinuxsecuritylaunchpad.net 88% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Dnsmasq affects Ubuntu 26.04 LTS and its derivatives, allowing remote attackers to crash the service or execute arbitrary code. The flaw arises from improper handling of BOOTREPLY packets when the --dhcp-split-relay option is enabled. This vulnerability can lead to denial of service and potential remote code execution. Users are advised to update their systems to the patched version dnsmasq 2.92-1ubuntu0.3. A standard system update will apply the necessary changes. The issue was disclosed on May 26, 2026, and impacts all systems running the affected versions of Dnsmasq. Ubuntu Pro offers extended security coverage for users managing multiple systems.

Key Points: • Dnsmasq vulnerability allows remote code execution and denial of service. • Affected systems include Ubuntu 26.04 LTS and its derivatives. • Users should update to dnsmasq version 2.92-1ubuntu0.3 to mitigate the risk.

ThreatCluster AI

Timeline

2026-05-26
Dnsmasq vulnerability disclosed
A critical vulnerability affecting Dnsmasq was announced, allowing remote attacks through specially crafted packets.
Ubuntu
2026-05-26
Ubuntu 26.04 LTS affected
The vulnerability specifically impacts Ubuntu 26.04 LTS and its derivatives, necessitating urgent updates.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story