Skip to content
Critical Dnsmasq Vulnerability Exposes Ubuntu Systems to Remote Attacks

Critical Dnsmasq Vulnerability Exposes Ubuntu Systems to Remote Attacks

First seen 27 May 2026, 03:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 28, 2026 at 03:37 UTC
  • Dnsmasq vulnerability allows remote code execution and denial of service.
  • Affected systems include Ubuntu 26.04 LTS and its derivatives.
  • Users should update to dnsmasq version 2.92-1ubuntu0.3 to mitigate the risk.

A critical vulnerability in Dnsmasq affects Ubuntu 26.04 LTS and its derivatives, allowing remote attackers to crash the service or execute arbitrary code. The flaw arises from improper handling of BOOTREPLY packets when the --dhcp-split-relay option is enabled. This vulnerability can lead to denial of service and potential remote code execution. Users are advised to update their systems to the patched version dnsmasq 2.92-1ubuntu0.3. A standard system update will apply the necessary changes. The issue was disclosed on May 26, 2026, and impacts all systems running the affected versions of Dnsmasq. Ubuntu Pro offers extended security coverage for users managing multiple systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 106d ago How this analysis works

Timeline

2026-05-26
Dnsmasq vulnerability disclosed
A critical vulnerability affecting Dnsmasq was announced, allowing remote attacks through specially crafted packets.
Ubuntu
2026-05-26
Ubuntu 26.04 LTS affected
The vulnerability specifically impacts Ubuntu 26.04 LTS and its derivatives, necessitating urgent updates.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed