VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation

2026-05-11T20:52:14Z1bedc108ee1e0fc0f0ad0777390b7d3d72fdfc576fc22bef2ababa4bada0cb06
AF_ALGCasdoorCopy-FailDHCPv6DNS-poisoningDNSSECDRC-INSIGHTGGUFLinux-kernelOllamaRadware-AlteonTerrarium','sandbox-escape','prototype-chain-traversalarbitrary-file-writecode-executiondata-exfiltrationdnsmasqheap-buffer-overflowheap-corruptionlocal-exploitlocal-privilege-escalationpath-traversalquantizationreflected-XSSremote-information-disclosureunauthenticated-config-modification

What happened

Collection of multiple high-impact vulnerabilities disclosed in May 2026 affecting open-source and commercial networking, identity, and ML tooling. Notable issues include multiple memory-safety and DNS/DHCP flaws in dnsmasq (heap buffer overflow, DNS cache poisoning, DNSSEC infinite loop/memory disclosure, DHCPv6 local root code execution), an authenticated path-traversal arbitrary file write in Casdoor, the Linux kernel AF_ALG "Copy Fail" local 4-byte write leading to reliable setuid binary in-memory corruption and privilege escalation, an unauthenticated configuration-modification endpoint (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
1bedc108ee1e0fc0f0ad0777390b7d3d72fdfc576fc22bef2ababa4bada0cb06
Enrichment time
2026-05-11T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation · Baitaphish